SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium
A system administrator is configuring a new web server that will host several customer-facing applications. To prevent attacks where malicious code is injected into the server's memory, potentially leading to arbitrary code execution, the administrator implements Data Execution Prevention (DEP). Which type of attack is DEP specifically designed to mitigate?
- ASQL Injection
- BBuffer Overflow
- CDenial of Service (DoS)
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: B. Buffer Overflow
Data Execution Prevention (DEP) marks memory regions as non-executable, preventing code from running in data segments. This is a primary defense against buffer overflow attacks, where malicious code is often injected into data buffers and then executed.
Why the other options are wrong
- A. SQL injection targets databases by manipulating queries, not memory execution.
- C. DoS attacks aim to make services unavailable, which is distinct from memory-based code execution.
- D. XSS involves injecting malicious client-side scripts into web pages, not server memory execution.
Data Execution Prevention (DEP)
A system-level memory protection feature that marks certain memory areas as non-executable, preventing code from running from data-only memory regions. This helps prevent certain types of malware and buffer overflow attacks.
- Prevents code execution from data segments of memory.
- Mitigates buffer overflow and similar memory corruption attacks.
- Implemented by hardware (NX bit) and/or software.
Memory trick: Memory needs guards to keep data from running wild.