缓冲区溢出攻击是网络安全的重大威胁,事先检测是否存在Shellcode是对抗缓冲区溢出攻击的有效手段。从Shellcode构成和特征出发,分类研究各种Sheltcode静态检测技术,分析比较它们的优缺点,在此基础上提出了一种检测方案并实现了一个原型系统。
Buffer overflow attack is one of the most serious threats for Internet security, and Shellcode detection is an effective method to combat this kind of attack. Starting from the structure and characteristics of Shellcode, different kinds of static detection techniques on Shell- code are studied, their advantages and shortcomings are analysed and compared, and finally a detection scheme based on these studies is proposed and its prototype is implemented.