The Experts below are selected from a list of 231 Experts worldwide ranked by ideXlab platform

Tzi-cker Chiueh - One of the best experts on this subject based on the ideXlab platform.

  • a binary rewriting defense against stack based buffer overflow attacks
    USENIX Annual Technical Conference, 2003
    Co-Authors: Manish Prasad, Tzi-cker Chiueh
    Abstract:

    Buffer overflow attack is the most common and arguably the most dangerous attack method used in Internet security breach incidents reported in the public literature. Various solutions have been developed to address the buffer overflow vulnerability problem in both research and commercial communities. Almost all the solutions that provide adequate protection against buffer overflow attacks are implemented as compiler extensions and hence require the source Code of the programs being protected to be available so that they can be re-compiled. While this requirement is reasonable in many cases, there are scenarios in which it is not feasible, e.g., legacy applications that are purchased from an outside vendor. The work reported in this paper explores application of static binary translation to protect Internet software from buffer overflow attacks. Specifically, we use a binary rewriting approach to augment existing Win32/Intel Portable Executable (PE) binary programs with a return address defense (RAD) mechanism [1], which protects the integrity of the return address on the stack with a redundant copy. This paper presents the disassembly and instrumentation issues involved in static binary translation, how our tool achieves satisfactory disassembly precision in the presence of indirect branches, position-independent Code sequences, hand crafted assembly Code and Arbitrary Code/data mixing, and how it ensures safe binary instrumentation in most practical cases. The paper reports our experiences with this approach, based on results of applying the resulting prototype to rewriting several commercial grade Windows applications (Ftp server, Telnet Server, DNS server, DHCP server, Outlook Express, MS FrontPage, MS Publisher, Telnet, Ftp, Winhlp, Notepad, CL compiler, MS NetMeeting, MS PowerPoint, MS Access, etc.), as well as experimentation with published buffer overflow exploits.

Alexander A Shvartsman - One of the best experts on this subject based on the ideXlab platform.

  • malicious takeover of voting systems Arbitrary Code execution on optical scan voting terminals
    ACM Symposium on Applied Computing, 2013
    Co-Authors: Russell J Jancewicz, Aggelos Kiayias, Laurent Michel, Alexander Russell, Alexander A Shvartsman
    Abstract:

    This work focuses on the AccuVote Optical Scan voting terminal (AV-OS) that is widely used in US elections. We present a new attack that can be delivered without opening the system enclosure, and without changing a single bit of the system's firmware. The attack is launched by inserting a maliciously programmed AV-OS memory card into the terminal. The card contains binary Code that exploits careless runtime memory management in the system's firmware to transfer control to alternate routines stored in the memory card. Once the control is taken by the injected Code, the voting system is forced to operate according to the wishes of the attacker. In particular, given that the attack results in the execution of the Arbitrary Code, an attacker can completely take over AV-OS operation and compromise the results of an election. It is also noteworthy that once a memory card is compromised it can be duplicated using the native function of the voting terminal. In some past elections it was observed that up to 6% of all memory cards were involved in card duplication. There exists a non-trivial possibility that the infection on one memory card can propagate virally to other cards in a given election. This development was performed without access to the source Code of the AV-OS system and without access to any internal vendor documentation. We note that this work is performed solely with the purpose of security analysis of AV-OS.

Hiroshi Kamabe - One of the best experts on this subject based on the ideXlab platform.

  • a new kind of nonbinary uniquely decodable Codes with Arbitrary Code length for multiple access adder channel
    Information Theory Workshop, 2018
    Co-Authors: Shan Lu, Jun Cheng, Hiroshi Kamabe
    Abstract:

    A kind of multiuser k-ary Codes for the multiple-access adder channel is proposed. Given any $T^{f}$-user and $T^{g}$-user k-ary uniquely decodable (UD) Codes with Code lengths f and g, respectively, a $(T^{f}\,+T^{g}\,+1)$-user k-ary UD Code with Code length $f+g$ is obtained. The proposed scheme has no restriction on the Code structure, e.g., affine, and can be constructed from any Arbitrary two UD Codes. Moreover, a recursive construction of a kind of k-ary UD Codes with Arbitrary Code length is given. The proposed Codes have the higher Code rate and the shorter Code length than those of the previous Codes for a fixed number of users.

Manish Prasad - One of the best experts on this subject based on the ideXlab platform.

  • a binary rewriting defense against stack based buffer overflow attacks
    USENIX Annual Technical Conference, 2003
    Co-Authors: Manish Prasad, Tzi-cker Chiueh
    Abstract:

    Buffer overflow attack is the most common and arguably the most dangerous attack method used in Internet security breach incidents reported in the public literature. Various solutions have been developed to address the buffer overflow vulnerability problem in both research and commercial communities. Almost all the solutions that provide adequate protection against buffer overflow attacks are implemented as compiler extensions and hence require the source Code of the programs being protected to be available so that they can be re-compiled. While this requirement is reasonable in many cases, there are scenarios in which it is not feasible, e.g., legacy applications that are purchased from an outside vendor. The work reported in this paper explores application of static binary translation to protect Internet software from buffer overflow attacks. Specifically, we use a binary rewriting approach to augment existing Win32/Intel Portable Executable (PE) binary programs with a return address defense (RAD) mechanism [1], which protects the integrity of the return address on the stack with a redundant copy. This paper presents the disassembly and instrumentation issues involved in static binary translation, how our tool achieves satisfactory disassembly precision in the presence of indirect branches, position-independent Code sequences, hand crafted assembly Code and Arbitrary Code/data mixing, and how it ensures safe binary instrumentation in most practical cases. The paper reports our experiences with this approach, based on results of applying the resulting prototype to rewriting several commercial grade Windows applications (Ftp server, Telnet Server, DNS server, DHCP server, Outlook Express, MS FrontPage, MS Publisher, Telnet, Ftp, Winhlp, Notepad, CL compiler, MS NetMeeting, MS PowerPoint, MS Access, etc.), as well as experimentation with published buffer overflow exploits.

Russell J Jancewicz - One of the best experts on this subject based on the ideXlab platform.

  • malicious takeover of voting systems Arbitrary Code execution on optical scan voting terminals
    ACM Symposium on Applied Computing, 2013
    Co-Authors: Russell J Jancewicz, Aggelos Kiayias, Laurent Michel, Alexander Russell, Alexander A Shvartsman
    Abstract:

    This work focuses on the AccuVote Optical Scan voting terminal (AV-OS) that is widely used in US elections. We present a new attack that can be delivered without opening the system enclosure, and without changing a single bit of the system's firmware. The attack is launched by inserting a maliciously programmed AV-OS memory card into the terminal. The card contains binary Code that exploits careless runtime memory management in the system's firmware to transfer control to alternate routines stored in the memory card. Once the control is taken by the injected Code, the voting system is forced to operate according to the wishes of the attacker. In particular, given that the attack results in the execution of the Arbitrary Code, an attacker can completely take over AV-OS operation and compromise the results of an election. It is also noteworthy that once a memory card is compromised it can be duplicated using the native function of the voting terminal. In some past elections it was observed that up to 6% of all memory cards were involved in card duplication. There exists a non-trivial possibility that the infection on one memory card can propagate virally to other cards in a given election. This development was performed without access to the source Code of the AV-OS system and without access to any internal vendor documentation. We note that this work is performed solely with the purpose of security analysis of AV-OS.