A Security Enhancement For Transparent Runtime Protection Against Code Injection Attacks

S. Raichal, Durga Devi V · 2011

Intrusion detection systems plays a Vital role in detecting the attacks before they can compromise softwares. Multivariant execution is an intrusion detection mechanism which executes slightly different several versions, called variants, of the same program in lockstep fashion. The variants usually have identical behavior under normal execution conditions. Though, when the variants are under attack, there are detectable differences in their execution behavior. At runtime process, a monitor compares the behavior of the variants at definite synchronization points and raises an alarm when a discrepancy is detected. The variants with a down-ward growing stack are given the exploit code the exploits succeed and an attacker is able to obtain illicit access to the target computer. When an upward growing stack variant is presented with the same exploit code, the variant continues to run since the buffer overflow writes into unused memory. In this project in order to recover the solution for code injection attack is to propose a scheduling algorithm to prevent the damage from the attack. The number of variants increases, the performance penalty of multivariant execution increases.

Read the paper · More papers on PaperTik