• Home
  • Search
  • Protecting C programs from attacks via invalid pointer dereferences
  • Cite Icon126
  • https://doi.org/10.1145/940071.940113Copy DOI Icon

Protecting C programs from attacks via invalid pointer dereferences

  • Sep 1, 2003
  • Suan Hsi Yong +1 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Writes via unchecked pointer dereferences rank high among vulnerabilities most often exploited by malicious code. The most common attacks use an unchecked string copy to cause a buffer overrun, thereby overwriting the return address in the function's activation record. Then, when the function "returns", control is actually transferred to the attacker's code. Other attacks may overwrite function pointers, setjmp buffers, system-call arguments, or simply corrupt data to cause a denial of service.A number of techniques have been proposed to address such attacks. Some are limited to protecting the return address only; others are more general, but have undesirable properties such as having a high runtime overhead, requiring manual changes to the source code, or forcing programmers to give up control of data representations and memory management.This paper describes the design and implementation of a security tool for C programs that addresses all these issues: it has a low runtime overhead, does not require source code modification by the programmer, does not report false positives, and provides protection against a wide range of attacks via bad pointer dereferences, including but not limited to buffer overruns and attempts to access previously freed memory. The tool uses static analysis to identify potentially dangerous pointer dereferences, and memory locations that are legitimate targets of these pointers. Dynamic checks are then inserted; if at runtime the target of an unsafe dereference is not in the legitimate set, a potential security violation is reported, and the program is halted.

Similar Papers
  • Conference Article

Security Risks in AI-Generated Code: A Comparative Analysis of Industry and Academic Benchmarks

  • Nov 21, 2025
  • Neha Kumari +3
  • Research Article
  • Citations44

ARCHER

  • Sep 01, 2003
  • ACM SIGSOFT Software Engineering Notes
  • Yichen Xie +2
  • Research Article
  • Citations135

SmashGuard: A Hardware Solution to Prevent Security Attacks on the Function Return Address

  • Jul 21, 2006
  • IEEE Transactions on Computers
  • H Ozdoganoglu +4
  • Conference Article
  • Citations87

Global Scheduling Not Required: Simple, Near-Optimal Multiprocessor Real-Time Scheduling with Semi-Partitioned Reservations

  • Nov 01, 2016
  • Bjorn B Brandenburg +1
  • Research Article

TRACE: Trusted Return-Path Authentication via Context and Lightweight Encryption for IoT Devices

  • Sep 23, 2025
  • IEEE Internet of Things Journal
  • Haijun Wang +7
  • Conference Article
  • Citations1

EPI: Efficient Pointer Integrity For Securing Embedded Systems

  • Sep 01, 2021
  • Mohamed Tarek Ibn Ziad +4
  • Conference Article
  • Citations2

Address code and arithmetic optimizations for embedded systems

  • Jun 25, 2003
  • J Ramanujam +3
  • Conference Article
  • Citations61

Make test-zesti: A symbolic execution solution for improving regression testing

  • Jun 01, 2012
  • Paul Dan Marinescu +1
  • PDF
  • Research Article
  • Citations16

Language and Obfuscation Oblivious Source Code Authorship Attribution

  • Jan 01, 2020
  • IEEE Access
  • Sarim Zafar +3
  • Conference Article
  • Citations74

A processor architecture defense against buffer overflow attacks

  • Jan 01, 2003
  • J.P Mcgregor +3
  • Conference Article
  • Citations26

Orchestrating data transfer for the cell/B.E. processor

  • Jun 07, 2008
  • Tong Chen +2
  • Book Chapter
  • Citations12

A Comparison of State-of-the-Art Machine Learning Models for OpCode-Based IoT Malware Detection

  • Jan 01, 2020
  • William Peters +3
  • Conference Article
  • Citations12

FIFO with Offsets: High Schedulability with Low Overheads

  • Apr 01, 2018
  • Mitra Nasri +2
  • Research Article

Source Code Implications for Malcode

  • Jan 01, 2006
  • Information Systems Security
  • Ken Dunham
  • Research Article

Hacking Back: Using Genetic Algorithms to Outsmart Hackers

  • Sep 01, 2025
  • Journal of Computer Science
  • Ghosoun Al Hindi +4
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.