首页> 外文会议>2013 IEEE 31st International Conference on Computer Design >JOP-alarm: Detecting jump-oriented programming-based anomalies in applications
【24h】

JOP-alarm: Detecting jump-oriented programming-based anomalies in applications

机译:JOP警报:检测应用程序中基于跳转的基于程序的异常

获取原文
获取原文并翻译 | 示例

摘要

Code Reuse-based Attacks (popularly known as CRA) are becoming increasingly notorious because of their ability to reuse existing code, and evade the guarding mechanisms in place to prevent code injection-based attacks. Among the recent code reuse-based exploits, Jump Oriented Programming (JOP) captures short sequences of existing code ending in indirect jumps or calls (known as gadgets), and utilizes them to cause harmful, unintended program behavior. In this work, we propose a novel, easily implementable algorithm, called JOP-alarm, that computes a score value to assess the potential for JOP attack, and detects possibly harmful program behavior. We demonstrate the effectiveness of our algorithm using published JOP code, and test the false positive alarm rate using several unmodified SPEC2006 benchmarks.
机译:基于代码重用的攻击(通常称为CRA)由于其重用现有代码的能力以及逃避适当的保护机制以防止基于代码注入的攻击而变得越来越臭名昭著。在最近的基于代码重用的攻击中,面向跳转的编程(JOP)捕获以间接跳转或调用(称为小工具)结尾的现有代码的短序列,并利用它们导致有害的,意外的程序行为。在这项工作中,我们提出了一种新颖的,易于实现的算法,称为JOP警报,该算法计算得分值以评估潜在的JOP攻击,并检测可能有害的程序行为。我们使用已发布的JOP代码演示了我们算法的有效性,并使用了几个未修改的SPEC2006基准测试了误报率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号