计算机应用 ›› 2010, Vol. 30 ›› Issue (8): 2130-2133.
• 信息安全 • 上一篇 下一篇
刘小珍1,李焕洲2
收稿日期:
修回日期:
发布日期:
出版日期:
通讯作者:
基金资助:
Received:
Revised:
Online:
Published:
摘要: 介绍了AVM2虚拟机的应用背景、安全研究价值和逃逸技术现状。从AVM2安全模型中的ABC验证缺陷入手,结合宿主环境漏洞和字节码仿真引擎漏洞,研究了基于验证欺骗的逃逸技术细节。最后根据当前研究成果,提出相应的防范策略,以及下阶段的改进目标。
关键词: AVM2虚拟机, 逃逸, 安全模型, 验证欺骗, 宿主环境
Abstract: The usage, value of security study, and present situation of escape techniques of AVM2 (ActionScript Virtual Machine 2) were introduced. Starting from the flaws of ABC verification in AVM2 security model, with host environment vulnerabilities and byte code simulation engine vulnerabilities, the technique details of the escape based on verification deception were then analyzed. Finally, according to the current research, proper strategies of defense and the target to improve in the next phase were given.
Key words: AVM2 Virtual Machine, Escape, Security Model, Verification Deception, host environment
刘小珍 李焕洲. 基于验证欺骗的AVM2虚拟机逃逸技术[J]. 计算机应用, 2010, 30(8): 2130-2133.
0 / 推荐
导出引用管理器 EndNote|Ris|BibTeX
链接本文: https://www.joca.cn/CN/
https://www.joca.cn/CN/Y2010/V30/I8/2130