Paper added: Protecting global and static variables from buffer overflow attacks without overhead
Submitted by Yves Younan on Mon, 2006-10-09 15:18Protecting global and static variables from buffer overflow attacks without overhead
Submitted by Yves Younan on Mon, 2006-10-09 15:12Authors: Yves Younan, Frank Piessens and Wouter Joosen
Published as: Technical Report CW463, Departement Computerwetenschappen, Katholieke Universiteit Leuven
Date: October 2006
Abstract: Many countermeasures exist to protect the stack and heap from code injection attacks, however very few countermeasures exist that will specifically protect global and static variables from attack. In this paper we suggest a way of protecting global and static variables from these type of attacks, with negligible performance and memory overheads.
Paper at ICICS 2006: Efficient protection against heap-based buffer overflows without resorting to magic
Submitted by Yves Younan on Sat, 2006-09-16 16:42Defcon 14 review
Submitted by Yves Younan on Tue, 2006-08-08 22:34Defcon 14
Submitted by Yves Younan on Sat, 2006-08-05 04:04Now that Usenix is over, I'm on my way to Defcon, I can finally meet some of the people who I've known for years online but never met because they're US-based.
Hopefully it will be as cool as Usenix was.
PS: Vancouver Airport has free wireless internet!
Paper at ACSAC 2006: Extended protection against stack smashing attacks without performance loss
Submitted by Yves Younan on Sat, 2006-08-05 04:02The paper I submitted to ACSAC (Annual Computer Security Applications Conference) was accepted!
The title is "Extended protection against stack smashing attacks without performance loss"
I'll post more details soon.
So I'll be attending ACSAC in December. If you'll be there let me know and we can grab a beer or something.
Usenix Security 2006 review
Submitted by Yves Younan on Sat, 2006-08-05 03:55Usenix Security ended just a few hours ago.
Overall it was pretty good, some of the refereed papers were impressive, others were only mediorce, it was very dependent on the track (and probably also my personal intererests because my colleagues often disagreed with me). The most interesting tracks were the ones on Software and Static analysis. I heard the Intrusion detection track was good as well, I didn't attend it because I was busy trying to convince my laptop to let me make some slides for the work in progress session.
Stephen McCamant got the best paper award for his paper Evaluating SFI for a CISC Architecture, which was definitely deserved. It was pretty impressive work, I'm looking forward to reading the paper.
Other talks which I found especially interesting: Keyboards and Covert Channels by Gaurav Shah, Milk or Wine by Andy Ozment, N-Variant Systems by Benjamin Cox, Taint-enhanced policy enforcement by Wei Xu. I've probably left some out though.
USENIX Security 2006
Submitted by Yves Younan on Tue, 2006-08-01 06:01I'm currently in Vancouver for USENIX Security 2006 where I'll be presenting a poster called "Applying machine-model based countermeasure design to improve security" on Thursday.
The technical track of the conference starts on Wednesday. Today I attended the "First Hotsec" workshop which aims to be a gathering for researchers to get feedback on ideas which are less conventional. I was impressed by the amount of feedback given to the authors by the attendees, makes me wish I had submitted my machinemodel stuff to the workshop.
Hopefully I'll get equally interesting feedback on my poster.
Website layout changed!
Submitted by Yves Younan on Wed, 2006-07-26 17:40Finally I found some time to update my sad looking website.
I'll be adding the old content back soon and then will start adding new content.
If you prefer the old "layout", it's still available here, but I won't be updating it anymore
