首页> 外文会议>International Conference on Smart Computing >Control-flow checking for intrusion detection via a real-time debug interface
【24h】

Control-flow checking for intrusion detection via a real-time debug interface

机译:通过实时调试接口控制流动检查进行入侵检测

获取原文

摘要

We propose a hardware-based intrusion detection approach called CONtrol-flow VERification SystEm (CONVERSE), which ensures control-flow integrity by verifying the destination of control-flow branches at runtime. Many techniques exist for an attacker to alter control-flow to trigger malicious behavior, such as stack and heap overflows which overwrite a return address or function pointer. Control-flow modification is used to enable a range of attacks including return-oriented programming attacks. By verifying branch target addresses at runtime, security exploits can be detected as illegal control-flow. Our approach uses the real-time hardware debug interface of the processor to extract branch target addresses at runtime with no performance overhead and no area overhead on-chip. Our approach is compatible with the IEEE-ISTO Nexus 5001 standard debugging interface which is open source and is implemented in a wide range of processors. By using an existing debug interfaces, our approach can be implemented at low cost using a commercial off-the-shelf (COTS) design strategy.
机译:我们提出了一种基于硬件的入侵检测方法,称为控制流程验证系统(匡威),该方法通过在运行时验证控制流程分支的目的地来确保控制流完整性。攻击者存在许多技术以改变控制流以触发恶意行为,例如覆盖返回地址或函数指针的堆栈和堆溢出。控制流修改用于启用一系列攻击,包括返回导向的编程攻击。通过在运行时验证分支目标地址,可以检测到安全漏洞作为非法控制流程。我们的方法使用处理器的实时硬件调试接口在运行时提取分支目标地址,而没有性能开销,也没有区域开销。我们的方法与IEEE-ISTO Nexus 5001标准调试接口兼容,该接口是开源的,并在各种处理器中实现。通过使用现有的调试界面,我们的方法可以使用商业现成(COTS)设计策略以低成本实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号