A qualitative framework for evaluating buffer overflow protection mechanisms
N. Raghu Kisore · International Journal of Information and Computer Security · 2016
In the last decade, a large number of buffer overflow protection mechanisms have been proposed in the literature. The exponential growth of the Internet has greatly enhanced the chances of a large scale cyber attack. In the absence of a quantitative model to answer the fundamental question in security 'how secure is secure enough?', we propose a qualitative framework based on which we review existing buffer overflow protection mechanisms to better understand their ability to prevent/slowdown a large scale cyber-attack. We use the proposed qualitative framework to evaluate 24 different buffer overflow protection mechanisms and finally conclude with a report card to summarise the security gaps in each of these mechanisms. We believe that this work at the least would serve as a reference to the research community and security practitioners in the software industry.