[PDF][PDF] Portably Solving File TOCTTOU Races with Hardness Amplification.
The file-system API of contemporary systems makes programs vulnerable to TOCTTOU (time
of check to time of use) race conditions. Existing solutions either help users to detect these
problems (by pinpointing their locations in the code), or prevent the problem altogether (by
modifying the kernel or its API). The latter alternative is not prevalent, and the former is just
the first step: programmers must still address TOCTTOU flaws within the limits of the existing
API with which several important tasks can not be accomplished in a portable …
of check to time of use) race conditions. Existing solutions either help users to detect these
problems (by pinpointing their locations in the code), or prevent the problem altogether (by
modifying the kernel or its API). The latter alternative is not prevalent, and the former is just
the first step: programmers must still address TOCTTOU flaws within the limits of the existing
API with which several important tasks can not be accomplished in a portable …
[HTML][HTML] Portably Solving File TOCTTOU Races with Hardness Amplification
DTT Hertz, DWD Da Silva - usenix.org
The file-system API of contemporary systems makes programs vulnerable to TOCTTOU (time
of check to time of use) race conditions. Existing solutions either help users to detect these
problems (by pinpointing their locations in the code), or prevent the problem altogether (by
modifying the kernel or its API). The latter alternative is not prevalent, and the former is just
the first step: programmers must still address TOCTTOU flaws within the limits of the existing
API with which several important tasks can not be accomplished in a portable …
of check to time of use) race conditions. Existing solutions either help users to detect these
problems (by pinpointing their locations in the code), or prevent the problem altogether (by
modifying the kernel or its API). The latter alternative is not prevalent, and the former is just
the first step: programmers must still address TOCTTOU flaws within the limits of the existing
API with which several important tasks can not be accomplished in a portable …
Showing the best results for this search. See all results