Scholay

学术搜索 · AI 审稿 · LaTeX 协作

SoftBound

作者:Santosh Nagarakatte, Yun Zhao, Milo M. K. Martin, Steve Zdancewic · 年份:2009 · DOI:10.1145/1542476.1542504 · 被引用次数:529 · 研究领域:Security and Verification in Computing、Parallel Computing and Optimization Techniques、Advanced Malware Detection Techniques

The serious bugs and security vulnerabilities facilitated by C/C++'s lack of bounds checking are well known, yet C and C++ remain in widespread use. Unfortunately, C's arbitrary pointer arithmetic, conflation of pointers and arrays, and programmer-visible memory layout make retrofitting C/C++ with spatial safety guarantees extremely challenging. Existing approaches suffer from incompleteness, have high runtime overhead, or require non-trivial changes to the C source code. Thus far, these deficiencies have prevented widespread adoption of such techniques.