Damien Howard

dblp:14/11073 · DBLP profile ↗
← Back
1ranked-venue papers
0as first author
0since 2021 · last 2012
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Systems and software security · 100%

Topics — the 3 heaviest of 3, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › memory safety
buffer overflow
0.112012
A Taxonomy of Buffer Overflow Characteristics · IEEE Trans. Dependable Secur. Comput. 2012
Systems and software security
memory safety
0.112012
A Taxonomy of Buffer Overflow Characteristics · IEEE Trans. Dependable Secur. Comput. 2012
Systems and software security
vulnerability discovery
0.112012
A Taxonomy of Buffer Overflow Characteristics · IEEE Trans. Dependable Secur. Comput. 2012

Methods — techniques the papers use, named apart from their topics

countermeasure analysis · 0.1
YearPublicationVenuePosition
2012 A Taxonomy of Buffer Overflow Characteristics
abstract
Significant work on vulnerabilities focuses on buffer overflows, in which data exceeding the bounds of an array is loaded into the array. The loading continues past the array boundary, causing variables and state information located adjacent to the array to change. As the process is not programmed to check for these additional changes, the process acts incorrectly. The incorrect action often places the system in a nonsecure state. This work develops a taxonomy of buffer overflow vulnerabilities based upon characteristics, or preconditions that must hold for an exploitable buffer overflow to exist. We analyze several software and hardware countermeasures to validate the approach. We then discuss alternate approaches to ameliorating this vulnerability.
Matt Bishop, Sophie Engle, Damien Howard, Sean Whalen
IEEE Trans. Dependable Secur. Comput.3