Back
ExamFull examExam paper only

02 02 15 1

Full exam for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Computer Security Exam Feb 02, 2015 First name: ________________________ Last name: ________________________ Matricola: ________________________ Signature: ________________________ Homeworks? [ ] (Y) [ ] (N) Instructions ● The exam is composed of 7 pages. ● Just as a cross

Computer SecurityFull exam

Document information

What's included in this study material

Full exam for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Computer Security Exam Feb 02, 2015 First name: ________________________ Last name: ________________________ Matricola: ________________________ Signature: ________________________ Homeworks? [ ] (Y) [ ] (N) Instructions ● The exam is composed of 7 pages. ● Just as a cross

Import quality: text was extracted directly from the original document.

Extracted content from the document

Representative passages recognised in different parts of the material. The full extracted text remains available to search, while this compact preview makes the page easier to read.

Page 1

Computer Security Exam Feb 02, 2015 First name: ________________________ Last name: ________________________ Matricola: ________________________ Signature: ________________________ Homeworks? [ ] (Y) [ ] (N) Instructions ● The exam is composed of 7 pages. ● Just as a cross check, tell us whether you have completed the homeworks, by putting an "X" mark appropriately. ● The exam is "closed books". Please put away in a non­suspicious place (i.e. not below the desk) any note, book, or similar. You will be expelled if, at any time, if you do not follow this rule. ● You are not allowed to communicate with other students, and you will be expelled from the exam if you do. ● Shut down and store electronic devices. They will be subject to inspection if found and you may be expelled if you are found using one. ● Please answer within the allowed space. Schemes are good, short answers are recommended. ● You can write in pen or pencil, any color, but ​avoid writing in red​. ● No extra paper is allowed. ● The answers ​must be written exclusively in the space provided​ below the questions. PROPOSED SOLUTION 1 of 7 Question 1 (4 points) CipStack​ is a new stack protection mechanism that is designed to protect against local attackers (e.g., users that can have a shell and launch binaries). ​CipStack​ works by inserting instructions in the prologue that push a value to the stack. This value is generated at compile time and is hardcoded in the binary. Then, during the epilogue, this value is popped from the stack and an appropriate instruction compares it with the hardcoded, expected one. In case of match, the program goes on, otherwise it is aborted. 1. Why this mechanism does not provide proper protection against stack overflows? The attacker can read the binary, for example using a…

Preview

First page of the document.

First page: 02 02 15 1