首页> 外文会议>International ISC Conference on Information Security and Cryptology >Tazhi: A novel technique for hunting trampoline gadgets of jump oriented programming (A class of code reuse attacks)
【24h】

Tazhi: A novel technique for hunting trampoline gadgets of jump oriented programming (A class of code reuse attacks)

机译:Tazhi:一种新技术,用于捕捉面向跳编程的蹦床小工具(一类代码重用攻击)

获取原文

摘要

Code reuse attacks enable attackers to manipulate the memory and execute their own code on a target system without the need to inject any operating code in the memory space. Jump Oriented Programming is known as a class of this type which has two different kinds of implementation. The main idea is to chain different sequences of instructions terminated to an indirect jump by using controller gadgets called dispatchers or trampolines. This paper focuses on the second type of implementations which uses trampoline gadgets. Finding useful trampolines in different libraries is an issue that considered here. This paper shows useful intended and unintended trampolines available in some famous versions of libraries in Windows and Linux platforms. Additionally, our searching algorithm and a comparison between results of trampolines are presented.
机译:代码重用攻击使攻击者可以在目标系统上操纵内存并执行自己的代码,而无需在内存空间中注入任何操作代码。面向跳转的编程被称为此类,它具有两种不同的实现。主要思想是通过使用称为调度程序或蹦床的控制器小工具,将终止于间接跳转的不同指令序列链接起来。本文重点介绍使用蹦床小工具的第二种实现方式。在不同的图书馆中找到有用的蹦床是这里要考虑的问题。本文显示了Windows和Linux平台上某些著名版本的库中可用的有用的有意和无意的蹦床。另外,提出了我们的搜索算法和蹦床结果之间的比较。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号