• Title/Summary/Keyword: Use After Free

Search Result 520, Processing Time 0.024 seconds

A Study on the Remove Use-After-Free Security Weakness (소프트웨어 개발단계 Use-After-Free 보안약점 제거방안 연구)

  • Park, Yong Koo;Choi, Jin Young
    • KIPS Transactions on Computer and Communication Systems
    • /
    • v.6 no.1
    • /
    • pp.43-50
    • /
    • 2017
  • Use-After-Free security problem is rapidly growing in popularity, especially for attacking web browser, operating system kernel, local software. This security weakness is difficult to detect by conventional methods. And if local system or software has this security weakness, it cause internal security problem. In this paper, we study ways to remove this security weakness in software development by summarize the cause of the Use-After-Free security weakness and suggest ways to remove them.

Automated Method for Detecting Use-After-Free Vulnerability of Windows System Calls Using Dynamic Symbolic Execution (동적 기호 실행을 이용한 윈도우 시스템 콜 Use-After-Free 취약점 자동 탐지 방법)

  • Kang, Sangyong;Lee, Gwonwang;Noh, Bongnam
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.27 no.4
    • /
    • pp.803-810
    • /
    • 2017
  • Recently, social security problems have been caused by the development of the software industry, and a variety of automation techniques have been used to verify software stability. In this paper, we propose a method of automatically detecting a use-after-free vulnerability on Windows system calls using dynamic symbolic execution, one of the software testing methods. First, a static analysis based pattern search is performed to select a target point. Based on the detected pattern points, we apply an induced path search technique that blocks branching to areas outside of interest. Through this, we overcome limitations of existing dynamic symbolic performance technology and verify whether vulnerability exists at actual target point. As a result of applying the proposed method to the Windows system call, it is confirmed that the use-after-free vulnerability, which had previously to be manually analyzed, can be detected by the proposed automation technique.

Reconstruction of Lower Extremities using Anterolateral thigh Perforator Free Flaps (전외측 대퇴부 천공지 유리피판을 이용한 하지 재건)

  • Kim, Tae Gon;Kang, Min Gu
    • Journal of Trauma and Injury
    • /
    • v.20 no.2
    • /
    • pp.119-124
    • /
    • 2007
  • Purpose: Management of the soft tissue defect in the lower extremity caused by trauma has always been difficult. Coverage with local and free muscle flaps after complete surgical excision of necrotic soft tissue and bone is a major strategy for treatment. There is no doubt that muscle provides a good blood supply, thus improving bone healing and increasing resistance to bacterial inoculation. However, accompanying problems are seen in cases with shallow dead space. This research was conducted to assess the efficacy of raising anterolateral thigh flaps and transferring them to the defect after complete debridement of non-viable, infected, and scar tissue as an alternative way to use local or free muscle flaps. Methods: From March 2005 to October 2007, 18 cases of soft tissue defect on lower extremities were re-surfaced with an anterolateral thigh perforator free flap. Results: The follow-up period ranged from 1 to 31 months with a mean of 15.9 months. All flaps survived completely. Satisfactory aesthetic and functional results were achieved. Under a two-point discrimination test, 13 patients had sensory recovery from 11 mm to 20 mm after 6 months postoperatively. Conclusion: Reconstruction of the lower extremity with anterolateral thigh perforator free flaps after appropriate debridement is a good alternative way to use local or free muscle flaps.

FRRmalloc : Efficient Use-After-Free prevention based on One-time-allocation and batch remapping (FRRmalloc:일회성 할당 및 리매핑 기반의 효율적인 Use-After-Free 방지)

  • Jeong-Hoon Kim;Yeong-Pil Cho
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2024.05a
    • /
    • pp.386-388
    • /
    • 2024
  • UAF(Use-After-Free)는 heap 영역에서 메모리 오염을 발생시킬 수 있는 취약점이다. UAF를 방지하기 위해 다양한 방법으로 관련 연구가 활발히 이루어지고 있지만, 아직까지 여러 오버헤드 측면에서 모두 좋은 성능을 발휘한 결과는 나오지 않고 있다. 할당자 수준에서의 수정을 통하여, UAF 취약점 방어를 보장하는 동시에 높은 성능과 낮은 오버헤드를 발생시킬 수 있는 방법을 제시한다. 본 논문에서는 UAF 취약점 및 관련 연구를 소개하고, 이를 기반으로 UAF 취약점에 대처할 수 있는 방법을 제시한다.

Analyze trends in Use-After-Free bug detection and blocking research (Use-After-Free 버그 탐지 및 예방 연구 동향 분석)

  • Jin-Hwan Kim;Yeong-Pil Cho
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2024.05a
    • /
    • pp.222-225
    • /
    • 2024
  • 전통적 프로그래밍 언어인 C/C++는 시스템 프로그래밍 언어로 널리 사용되고 있으며, 이는 저수준 메모리 제어와 하드웨어 상호작용 등의 특성 때문이다. 하지만 C/C++가 가지고 있는 특성중 하나인 저수준 메모리 제어는 프로그래머가 직접 메모리를 관리해야한다. 다양한 메모리 버그들중에서 특히 Use-after-free버그는 오래전부터 현재까지 해결되지 않은 버그로써 존재하고 있으며, 이는 프로그래머가 수동으로 메모리를 관리함으로써 발생한다. 이 버그를 예방 및 감지하기 위한 연구가 현재까지도 활발하게 진행되고 있다. 이 버그를 차단 및 감지하는 연구들의 동향을 분석하여 앞으로의 관련 연구의 지속적인 필요성을 제시한다.

Reconstruction of the Cervical Esophagus Using the Free Jejunal Graft (경부 식도협착 재건술에 있어서 유리공장 이식편의 이용)

  • 지청현
    • Journal of Chest Surgery
    • /
    • v.24 no.12
    • /
    • pp.1232-1237
    • /
    • 1991
  • The cervical esophageal stricture has various surgical modalities and difficulties in reconstruction. We had experienced a case of successful reconstruction of the cervical esophageal restenosis using the free jejunal graft, on 30 year old man had had esophageal stricture after ingestion of lye. He had undergone colon interposition[esophagocologastrostomy] with left colon feeding gastrostomy. But restenosis was occurred just above of the cervical esophagocolostomy site several times of balloon dilatation were failed. So, we decided to use of the free jejunal graft. The free jejunal graft was isolated about 15cm length with it`s vascular arcades. The graft was irrigated with the mixed solution as isotonic saline, heparin and papaverine chloride. The artery of graft was anastomosed to the branch of the external carotid artery in end to side with continuous sutures of the 8.0 Prolene. The vein of the graft was anastomosed to the branch of the anterior facial vein in end to end with continuous sutures of the 8.0 prolene. Postoperative course was uneventful and the patient was discharged after removal of the tracheostomy cannula and gastrostomy tube.

  • PDF

Quality Analysis of the Free Amino Acids during the Early Development Stages of Hynobius leechi (한국산 도롱뇽(Hynobius Leechi BOULENGER 의 초기발생단계에 있어서의 유리 아미노산의 정성분석)

  • 강영선;하두봉;한원택
    • The Korean Journal of Zoology
    • /
    • v.4 no.2
    • /
    • pp.13-19
    • /
    • 1961
  • Free amino acids at five different developemntal stages (Gastrulation-Hatching -out stage) of Hynobius leechi BOULENGER were analyzed qualitatively by the use of paper paitition chromatography. It was found that the number of free amino acids increased as the development proceeded. The free amino acids identified at each stages are as follows : Gastrulation stage : Alaninie, Aspartic acid, Glutamin acid, Histidine, Methionine. Neural plate formation stage : Alanine , Aspartic acid, Glutamic acid, Glycine, Histidine, MEthionine, Phenylalanine, Proline, Serine, Trypotophan. Middle tail-bud stage : Alanine, Arginine, Asparagine,Aspartic acid, Citrulline, Glutamic acid, Glycine, Histidie,Hydroxyproline, Proline, Leucine, Methionine, Ornithine, Phenylalanine, Serine, Threonine, Tryptophan. Late tail-bud stage : Alanine, Arginine, Asparagine, Aspartic acid, Citrulline, Glutamic acid. Glycine, Histidine, Hydroxyproline, Leucine, Methionine, Ornithine, Phenylalanine, Proline, Serine, Threonine, Tryptophan, Valine. Hatching -out stage : the same with the late tail-bud stage. It seems probable that the metabolic systems of amino acids before and after the middle tail-bud stage are quite different from each other. Before the middle tail=-bud stage, the reaction system of amino acids is thought not to be completed while after that stage the system has been completed , because in the former period of the development , the number of freeamino acids increased rapidly with the development , and after that stage, there is practically no change in the number of free amino acids.

  • PDF

A Study on Defense Technique Against Use-After-Free Attacks Using MTE (MTE 를 활용한 사용 후 해제 공격 방어기법 연구)

  • Yunseong Hwang;Junseung You;Yunheung Paek
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2024.05a
    • /
    • pp.279-282
    • /
    • 2024
  • The Use-after-free (UAF) bug is a long-standing temporal memory safety issue. To prevent UAF attacks, two commonly used approaches are lock-and-key and pointer nullification. Recently, ARM architecture supports the Memory Tagging Extension (MTE) that implemented a lock-and-key mechanism using a 4-bit tag during memory access. Previous research proposed a virtual address tagging scheme utilizing MTE to prevent UAF attacks. In this paper, we aimed to measure a simplified version of the previously proposed virtual address tagging scheme on real machines supporting MTE by implementing a simple module and conducting experiments.

Lead-free Solder Technology and Reliability for Automotive Electronics (자동차 전장용 무연 솔더 기술)

  • Lee, Soon-Jae;Jung, Jae-Pil
    • Journal of the Microelectronics and Packaging Society
    • /
    • v.22 no.3
    • /
    • pp.1-7
    • /
    • 2015
  • In this study, properties of Pb-free solders for automotive electronics parts were discussed. Lead-free solders for electronics became important after RoHS (Restriction of the use of certain Hazardous Substances) to avoid environmental pollution. Also the growing electronic rate in automotive parts and ELV (End-of Life Vehicles) make Pb-free solder for automotive electronics to be inevitable trend. Definitely, Pb-free solder for automotive electronics should have good wettability, basic strength, but need more reliability than other solders, since it has harsh condition like high temperature, humidity and engine vibration. Thus, shear strength test, thermal shock, drop test and many others are needed to ensure the high reliability. This study describes the properties and requirements of Pb-free solders for automotive electronics.

Salvage of Esophageal Reconstruction with Colon Free Flap (대장유리피판(Colon Free Flap)을 이용한 식도재건의 구제술)

  • Lee, Sang Woo;Min, Kyung Won
    • Archives of Plastic Surgery
    • /
    • v.33 no.2
    • /
    • pp.245-248
    • /
    • 2006
  • Besides gastric pull-up or colonic interposition, microvascular technique in esophageal reconstruction has been approved reliable methods. When free intestinal transfer is considered, jejunal free flap is commonly used. We treated the patient who had undergone reconstruction with a right colon interposition and suffered from inability of swallowing because of stricture and necrosis of the interposed flap. Although we have planned jejunal free transfer, we couldn't use jejunum due to adhesion by previous gastrojejunostomy and colon interposition. Salvage procedure with microvascualr free left colon flap was executed successfully. After 9 month follow-up, the patient was able to consume a normal diet.