Virtualization-assisted Framework for Prevention of Software Vulnerability Based Security Attacks

Najwa Aaraj, Anand Raghunathan, Niraj Kumar Jha · 2007

Virtualization is a useful technology for addressing security concerns since it allows for the creation of isolated software execution environments, e.g., for separation of the sensitive parts of a system from the complex, untrusted parts. In this paper, we describe a tool for dynamically detecting and preventing software vulnerabilities that exploits the availability of virtualized (isolated) execution environments. A program that is not itself malicious, but could have vulnerabilities, is first safely executed within a virtualized Testing environment, wherein its execution is traced using dynamic binary instrumentation and checked against extensive security policies that express the behavioral patterns associated with various vulnerability exploits. The program’s execution trace is represented using a hybrid model that consists of regular expressions along with data invariants in order to capture both control and data flow. The behavioral model of the program’s exercised execution paths. The

Read the paper · More papers on PaperTik