TY - GEN
T1 - Address-space randomization for windows systems
AU - Li, Lixin
AU - Just, James E.
AU - Sekar, R.
PY - 2006
Y1 - 2006
N2 - Address-space randomization (ASR) is a promising solution to defend against memory corruption attacks that have contributed to about three-quarters of US-CERT advisories in the past few years. Several techniques have been proposed for implementing ASR on Linux, but its application to Microsoft Windows, the largest monoculture on the Internet, has not received as much attention. We address this problem in this paper and describe a solution that provides about 15-bits of randomness in the locations of all (code or data) objects. Our randomization is applicable to all processes on a Windows box, including all core system services, as well as applications such as web browsers, office applications, and so on. Our solution has been deployed continuously for about a year on a desktop system used daily, and is robust enough for production use.
AB - Address-space randomization (ASR) is a promising solution to defend against memory corruption attacks that have contributed to about three-quarters of US-CERT advisories in the past few years. Several techniques have been proposed for implementing ASR on Linux, but its application to Microsoft Windows, the largest monoculture on the Internet, has not received as much attention. We address this problem in this paper and describe a solution that provides about 15-bits of randomness in the locations of all (code or data) objects. Our randomization is applicable to all processes on a Windows box, including all core system services, as well as applications such as web browsers, office applications, and so on. Our solution has been deployed continuously for about a year on a desktop system used daily, and is robust enough for production use.
UR - https://www.scopus.com/pages/publications/39049166231
U2 - 10.1109/ACSAC.2006.10
DO - 10.1109/ACSAC.2006.10
M3 - Conference contribution
AN - SCOPUS:39049166231
SN - 0769527167
SN - 9780769527161
T3 - Proceedings - Annual Computer Security Applications Conference, ACSAC
SP - 329
EP - 338
BT - Proceedings - Annual Computer Security Applications Conference, ACSAC
T2 - 22nd Annual Computer Security Applications Conference, ACSAC 2006
Y2 - 11 December 2006 through 15 December 2006
ER -