Outline for October 13, 2006
Reading
: §23.3–23.4
Greetings and felicitations!
Puzzle of the day
Examples of Flaw Hypothesis Methodology
Burroughs system
Vulnerability Models
PA model
RISOS
NRL
Aslam
Example Flaws
fingerd buffer overflow
xterm race condition
RISOS
Goal: Aid managers, others in understanding security issues in OSes, and work required to make them more secure
Incomplete parameter validation—failing to check that a parameter used as an array index is in the range of the array;
You can also obtain a PDF version of this.
Version of October 16, 2006 at 9:25 AM