Technical reports:
Concurrency Attacks
Junfeng Yang; Ang Cui; John Martin Gallagher; Salvatore Stolfo; Lakshminarasimhan Sethumadhavan
Downloads:
- Title:
- Concurrency Attacks
- Author(s):
-
Yang, Junfeng
Cui, Ang
Gallagher, John Martin
Stolfo, Salvatore
Sethumadhavan, Lakshminarasimhan - Date:
- 2011
- Type:
- Technical reports
- Department:
- Computer Science
- Permanent URL:
- http://hdl.handle.net/10022/AC:P:10681
- Series:
- Columbia University Computer Science Technical Reports
- Part Number:
- CUCS-028-11
- Publisher:
- Department of Computer Science, Columbia University
- Publisher Location:
- New York
- Abstract:
- Just as errors in sequential programs can lead to security exploits, errors in concurrent programs can lead to concurrency attacks. In this paper, we present an in-depth study of concurrency attacks and how they may affect existing defenses. Our study yields several interesting findings. For instance, we find that concurrency attacks can corrupt non-pointer data, such as user identifiers, which existing memory-safety defenses cannot handle. Inspired by our findings, we propose new defense directions and fixes to existing defenses.
- Subject(s):
- Computer science
- Item views:
- 207