【24h】

PMU-extended Hardware ROP Attack Detection

机译:PMU扩展的硬件ROP攻击检测

获取原文

摘要

Return Oriented Programming is one of the major challenges for software security nowadays. It can bypass Data Execution Prevention (DEP) mechanism by chaining short instruction sequences from existing code together to induce arbitrary code execution. Existing defenses are usually trade-offs between practicality, security, and performance. In this paper, we propose PMUe, a low-cost hardware ROP detection approach that detects ROP attack based on three inherent properties of ROP. It is transparent to user applications and can be regarded as a small extension to existing Performance Monitoring Unit in commodity processors. Our evaluation demonstrates that PMUe can effectively detect ROP attack with negligible performance overhead.
机译:面向返回的编程是当今软件安全的主要挑战之一。通过将来自现有代码的短指令序列链接在一​​起以引发任意代码执行,它可以绕过数据执行保护(DEP)机制。现有的防御措施通常是在实用性,安全性和性能之间进行权衡。在本文中,我们提出了PMUe,一种低成本的硬件ROP检测方法,它基于ROP的三个固有属性来检测ROP攻击。它对用户应用程序是透明的,可以看作是商品处理器中现有性能监视单元的一个小扩展。我们的评估表明,PMUe可以有效地检测ROP攻击,而性能开销却可以忽略不计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号