Skip to main content

Table 1 Defense results of DSSR applications in two hours

From: Feedback control can make data structure layout randomization more cost-effective under zero-day attacks

Programs

CVE #

Bugs

Data Structure

Static DSLR

SALADSPlus

openssl-0.9.6d

CVE-2002-0656

KEY ARG bug (CVE-2002-0656 2002)

ssl_session_st

×

√

   

malloc_chunk

  

glibc-2.2.2

CVE-2015-0235

GHOST bug (CVE-2015-0235 2015)

malloc_chunk

×

√

openssh-2.1.1

CVE-2001-0144

CRC-32 bug (CVE-2001-0144 2001)

passwd

×

√

apache-1.1.1

CVE-1999-0071

Cookie bug (CVE-1999-0071 1999)

timeval

×

√

openssl-1.0.1c

CVE-2014-0160

Heartbleed bug (CVE-2014-0160 2014)

N/A

×

×

openssh-2.1.1

CVE-2001-0144

do_authentication (CVE-2001-0144 2001)

N/A

×

×