首页> 外文会议>ICT systems security and privacy protection >Gadget Weighted Tagging: A Flexible Framework to Protect Against Code Reuse Attacks
【24h】

Gadget Weighted Tagging: A Flexible Framework to Protect Against Code Reuse Attacks

机译:小工具加权标记:防止代码重用攻击的灵活框架

获取原文
获取原文并翻译 | 示例

摘要

The code reuse attack (CRA) has become one of the most common attack methods. In this paper, we propose gadget weighted tagging (GWT), a flexible framework to protect against CRAs. In GWT, we firstly find all possible gadgets, which can be used in CRAs. Then, we attach weighted tags to these gadgets based on the lengths and types of the gadgets, and the weighted values are configurable. At last, GWT monitors the weighted tag information at runtime to detect and prevent CRAs. Furthermore, combining with the rule-based CFI, GWT+CFI can precisely confirm the gadget start and greatly reduce the number of possible gadgets, compared to the baseline GWT. We implement a hardware/software co-design framework to support GWT and GWT+CFI. The results show that the performance overheads of GWT and GWT+CFI are 2.31% and 3.55% respectively, and GWT can defeat variants of CRAs, especially those generated by automated tools.
机译:代码重用攻击(CRA)已成为最常见的攻击方法之一。在本文中,我们提出了小工具加权标记(GWT),这是一种防止CRA的灵活框架。在GWT中,我们首先找到可以在CRA中使用的所有可能的小工具。然后,我们根据小工具的长度和类型将加权标签附加到这些小工具上,并且加权值是可配置的。最后,GWT在运行时监视加权标签信息,以检测和阻止CRA。此外,与基准GWT相比,与基于规则的CFI结合,GWT + CFI可以精确地确认小工具的开始并大大减少了可能的小工具的数量。我们实施了一个硬件/软件协同设计框架来支持GWT和GWT + CFI。结果表明,GWT和GWT + CFI的性能开销分别为2.31%和3.55%,并且GWT可以击败CRA的变体,尤其是由自动化工具生成的变体。

著录项

  • 来源
  • 会议地点 Rome(IT)
  • 作者单位

    Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China,University of Chinese Academy of Sciences, Beijing, China;

    Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China,University of Chinese Academy of Sciences, Beijing, China;

    Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China,University of Chinese Academy of Sciences, Beijing, China;

    Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China,University of Chinese Academy of Sciences, Beijing, China;

    Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China,University of Chinese Academy of Sciences, Beijing, China;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号