• Title/Summary/Keyword: Bug

Search Result 314, Processing Time 0.023 seconds

Buffer Overflow Attack and Defense Techniques

  • Alzahrani, Sabah M.
    • International Journal of Computer Science & Network Security
    • /
    • v.21 no.12
    • /
    • pp.207-212
    • /
    • 2021
  • A buffer overflow attack is carried out to subvert privileged program functions to gain control of the program and thus control the host. Buffer overflow attacks should be prevented by risk managers by eradicating and detecting them before the software is utilized. While calculating the size, correct variables should be chosen by risk managers in situations where fixed-length buffers are being used to avoid placing excess data that leads to the creation of an overflow. Metamorphism can also be used as it is capable of protecting data by attaining a reasonable resistance level [1]. In addition, risk management teams should ensure they access the latest updates for their application server products that support the internet infrastructure and the recent bug reports [2]. Scanners that can detect buffer overflows' flaws in their custom web applications and server products should be used by risk management teams to scan their websites. This paper presents an experiment of buffer overflow vulnerability and attack. The aims to study of a buffer overflow mechanism, types, and countermeasures. In addition, to comprehend the current detection plus prevention approaches that can be executed to prevent future attacks or mitigate the impacts of similar attacks.

A study on Dirty Pipe Linux vulnerability

  • Tanwar, Saurav;Kim, Hee Wan
    • International Journal of Internet, Broadcasting and Communication
    • /
    • v.14 no.3
    • /
    • pp.17-21
    • /
    • 2022
  • In this study, we wanted to examine the new vulnerability 'Dirty Pipe' that is founded in Linux kernel. how it's exploited and what is the limitation, where it's existed, and overcome techniques and analysis of the Linux kernel package. The study of the method used the hmark[1] program to check the vulnerabilities. Hmark is a whitebox testing tool that helps to analyze the vulnerability based on static whitebox testing and automated verification. For this purpose of our study, we analyzed Linux kernel code that is downloaded from an open-source website. Then by analyzing the hmark tool results, we identified in which file of the kernel it exists, cvss level, statistically depicted vulnerabilities on graph which is easy to understand. Furthermore, we will talk about some software we can use to analyze a vulnerability and how hmark software works. In the case of the Dirty Pipe vulnerability in Linux allows non-privileged users to execute malicious code capable of a host of destructive actions including installing backdoors into the system, injecting code into scripts, altering binaries used by elevated programs, and creating unauthorized user profiles. This bug is being tracked as CVE-2022-0847 and has been termed "Dirty Pipe"[2] since it bears a close resemblance to Dirty Cow[3], and easily exploitable Linux vulnerability from 2016 which granted a bad actor an identical level of privileges and powers.

OAPR-HOML'1: Optimal automated program repair approach based on hybrid improved grasshopper optimization and opposition learning based artificial neural network

  • MAMATHA, T.;RAMA SUBBA REDDY, B.;BINDU, C SHOBA
    • International Journal of Computer Science & Network Security
    • /
    • v.22 no.4
    • /
    • pp.261-273
    • /
    • 2022
  • Over the last decade, the scientific community has been actively developing technologies for automated software bug fixes called Automated Program Repair (APR). Several APR techniques have recently been proposed to effectively address multiple classroom programming errors. However, little attention has been paid to the advances in effective APR techniques for software bugs that are widely occurring during the software life cycle maintenance phase. To further enhance the concept of software testing and debugging, we recommend an optimized automated software repair approach based on hybrid technology (OAPR-HOML'1). The first contribution of the proposed OAPR-HOML'1 technique is to introduce an improved grasshopper optimization (IGO) algorithm for fault location identification in the given test projects. Then, we illustrate an opposition learning based artificial neural network (OL-ANN) technique to select AST node-level transformation schemas to create the sketches which provide automated program repair for those faulty projects. Finally, the OAPR-HOML'1 is evaluated using Defects4J benchmark and the performance is compared with the modern technologies number of bugs fixed, accuracy, precession, recall and F-measure.

Building a Dynamic Analyzer for CUDA based System.

  • SALAH T. ALSHAMMARI
    • International Journal of Computer Science & Network Security
    • /
    • v.23 no.8
    • /
    • pp.77-84
    • /
    • 2023
  • The utilization of GPUs on general-purpose computers is currently on the rise due to the increase in its programmability and performance requirements. The utility of tools like NVIDIA's CUDA have been designed to allow programmers to code algorithms by using C-like language for the execution process on the graphics processing units GPU. Unfortunately, many of the performance and correctness bugs will happen on parallel programs. The CUDA tool support for the parallel programs has not yet been actualized. The use of a dynamic analyzer to find performance and correctness bugs in CUDA programs facilitates the execution of sophisticated processes, especially in modern computing requirements. Any race conditions bug it will impact of program correctness and the share memory bank conflicts to improve the overall performance. The technique instruments the programs in a way that promotes accessibility of the memory locations accessed by different threads well as to check for any bugs in the code of a program. The instrumented source code will be used initiated directly in the device emulation code of CUDA to send report for the user about all errors. The current degree of automation helps programmers solve subtle bugs in highly complex programs or programs that cannot be analyzed manually.

Comparison of Effects of Static Core Training and Additional Dynamic Core Training in Young Adults: An Experimental Study

  • Namjeong Cho;Hyunjoong Kim
    • Physical Therapy Rehabilitation Science
    • /
    • v.12 no.1
    • /
    • pp.56-61
    • /
    • 2023
  • Objective: Core training is a key exercise for conditioning and fitness programs, injury prevention, and more. This study aimed to find out the effect of adding dynamic core training, which is frequently prescribed in clinical practice, on dynamic balance and muscle activity compared to conventional static core training. Design: An experimental study Methods: This study is an experimental pilot study of prospective parallel design. Six healthy young adults were allocated to static core training group (SCG; crunch and plank) and blended group (BG; crunch, plank, and dead bug exercise) for two weeks to perform core training. Dynamic balance and muscle activity (erector spinae, rectus abdominis) were measured for all participants before and after core training. Results: All six healthy young adults enrolled completed the study. No significant difference was found before and after 6 sessions of core training in each group (P>0.05). Likewise, no significant difference was found in the results of the difference comparison between groups (P>0.05). Conclusions: In conclusion, in this experimental study, no difference was found when dynamic core training was added. Although the results before and after core training did not show improvement in dynamic balance and muscle activity, a randomized controlled trial is needed considering the results of previous studies and the limitations of this experimental study.

Experimental Study on Magnetic Compaction for Reducing Bughole of Free-Form Concrete Panels (비정형 콘크리트 패널 표면 공극저감을 위한 자력 다짐 실험연구)

  • Youn, Jong-Young;Kim, Ji-Hye;Kim, Hye-Kwon;Lee, Donghoon
    • Proceedings of the Korean Institute of Building Construction Conference
    • /
    • 2023.05a
    • /
    • pp.25-26
    • /
    • 2023
  • Free-form buildings serve as landmarks, and interest and demand are increasing. However, in the case of free-form concrete members, different curved surfaces are required depending on the location where they are used, and the formwork is custom-made and used. Concrete is poured into the manufactured formwork to produce FCP (Free-form Concrete Panel). However, since it is an atypical building that requires precise curvature, compaction cannot be performed after concrete is poured. This leads to the occurrence of bughole, which reduce the strength and aesthetics of concrete. Therefore, in this study, we intend to conduct basic experiments to develop a magnetic compaction device that can be used for FCP. As a result of the experiment, it was confirmed that the bug hole was improved when the magnetic compaction device was applied, and there was no significant difference in compressive strength and flexural strength. This technology can be used in the field of Free-form concrete where it is difficult to perform compaction work, and it is expected to be used as a basic research related to technology for new automatic compaction.

  • PDF

Ovicidal Effect of Plant Extract Mixture Against Seven Major Insect Pests (7종의 주요 해충에 대한 식물추출물의 살란 효과)

  • Hee-A Lee;Young Su Lee
    • Korean journal of applied entomology
    • /
    • v.63 no.1
    • /
    • pp.75-76
    • /
    • 2024
  • The ovicidal effect of plant extract mixture (5%cinnamon extract + 10% citronella oil + 30% citrus oil + 10% derris extract + 20% neem extract + 25% penetrating surfactant) against several major insect pests was tested using the spraying method. In the case of stink bugs, eggs tended to die during hatching. When treated with a plant extract mixture (500-times solution), mortality for Halyomorpha halys, Riptortus clavatus, Eurydema dominulus, Trialeurodes vaprarorium, Bemisia tabaci, Spodoptera exigua, and Agrotis ipsilon reached as high as 100%. Therefore, it is believed that industrialization will be feasible in the future.

Chemical Soil Treatments for Nematode Control on Peanut (땅콩기생(寄生) 선충(線虫) 방제(防除)에 관(關)한 연구(硏究))

  • Choi, Young Eoun;Kim, Ho Yul
    • Current Research on Agriculture and Life Sciences
    • /
    • v.1
    • /
    • pp.41-46
    • /
    • 1983
  • Nine species of plant parasitic nematodes, Aphelenchoides besseyi, Aphelenchus avenae, Criconemoides informis, Helicotylenchus dihystera, Meloidogyne arenaria, Meloidogyne hapla, Pratylenchus minyus and Tylenchus sp. Were found in peanut field in Korea. Chemicals used were; Telon C-17, Mocap 10G and Carbofuran 3G for control peanut parasitic nematodes. All chemicals reduced nematode populations but varied in effectiveness. Telon C-17 was especially effective against Meloidogyne hapla, the principal species on peanut and resulted in significant yield increased than the control. Plant height, number of branches and dry weight of peanut were increased over the nontreated control by chemical soil treatments.

  • PDF

Attractiveness of Plautia stali (Hemiptera: Pentatomidae) Aggregation Pheromone Produced in Korea (국산 갈색날개노린재 집합페로몬의 유인력)

  • Jang, Sin-Ae;Cho, Jin-Hoon;Park, Chung-Gyoo
    • The Korean Journal of Pesticide Science
    • /
    • v.14 no.2
    • /
    • pp.164-169
    • /
    • 2010
  • Methyl (E,E,Z)-2,4,6-decatrienoate is the aggregation pheromone of brown-winged stink bug Plautia stali (Hemiptera: Pentatomidae). Attractiveness of the pheromone synthesized in Korea was compared with that of synthesized in Japan in the field. A lure filled with hexane was used as a control treatment. Catches in trap baited with Korean pheromone was significantly higher than that baited with Japanese one only in one orchard out of three sweet persimmon orchards in 2008. However there was no difference in trap catches between Korean and Japanese pheromones at three sites in 2009. Gas chromatography analysis showed that the components of both pheromones were not different each other. Monitoring of P. stali seasonal fluctuation using Korean pheromone showed that the bugs were most captured in August, 2008 and in September, 2009.

Feeding Effects of Halyomopha halys (Hemiptera: Pentatomidae) on Fruit Drop and Decay Rate in Mandarin Citrus Orchards (감귤원에서 썩덩나무노린재 감귤과실 흡즙이 낙과 및 부패에 미치는 영향)

  • Kim, Su bin;Jang, Yong Seok;Kim, Dong-Soon
    • Korean journal of applied entomology
    • /
    • v.54 no.2
    • /
    • pp.121-125
    • /
    • 2015
  • This study was conducted to examine the feeding effect of Halyomorpha halys ($St{\aa}l$) (Hemiptera: Pentatomidae) on the fruit drop and decay rate of Mandarin citrus fruits (Citrus unshiu). The feeding of H. halys before fruit coloring caused a severe fruit drop, while the feeding after fruit coloring induced a low level of fruit drop. However, the feeding of H. halys before or after fruit coloring did not induce significant fruit decay during cold storage. The results are expected to be useful in managing H. hlays of late season mandarine, because citrus farmers follow calendar spray to prevent fruit drop and fruit decay.