首页> 外文会议>IEEE Global Communications Conference >Defending against ROP Attacks with Nearly Zero Overhead
【24h】

Defending against ROP Attacks with Nearly Zero Overhead

机译:防御开销几乎为零的ROP攻击

获取原文

摘要

Return-Oriented Programming (ROP) is a sophisticated exploitation technique that is able to drive target applications to perform arbitrary unintended operations by constructing a gadget chain reusing existing small code sequences (gadgets) collected across the entire code space. In this paper, we propose to address ROP attacks from a different angle-shrinking available code space at runtime. We present ROPStarvation , a generic and transparent ROP countermeasure that defend against all types of ROP attacks with almost zero run-time overhead. ROPStarvation does not aim to completely stop ROP attacks, instead it attempts to significantly increase the bar by decreasing the possibility of launching a successful ROP exploit in reality. Moreover, shrinking available code space at runtime is lightweight that makes ROPStarvation practical for being deployed with high performance requirement. Results show that ROPStarvation successfully reduces the code space of target applications by 85%. With the reduced code segments, ROPStarvation decreases the probability of building a valid ROP gadget chain by 100% and 83% respectively, with the assumptions that whether the adversary knows the vulnerable applications are protected by ROPStarvation . Evaluations on the SPEC CPU2006 benchmark show that ROPStarvation introduces nearly zero (0.2% on average) run-time performance overhead.
机译:以返回返回的编程(ROP)是一种复杂的开发技术,可以通过构建在整个代码空间中收集的现有小型代码序列(小工具)来驱动目标应用来执行任意意外操作。在本文中,我们建议在运行时从不同的角度缩小的可用代码空间解决ROP攻击。我们提出了罗波塔维化,一种透明和透明的ROP对策,这些对策抵御各种类型的ROP攻击,几乎零运行时间开销。 Ropstarvation并不旨在完全停止ROP攻击,而是通过降低推动成功的ROP利用的可能性来显着增加酒吧。此外,在运行时缩小可用的代码空间是重量轻,使ROPStarvation能够进行高性能要求。结果表明,Ropstarvation成功将目标应用程序的代码空间降低了85%。通过降低的代码段,Ropstarvation分别将有效的ROP小工具链的概率降低100%和83%,假设对手是否知道易受攻击的应用受到蠕动保护。 SPEM CPU2006基准测试表明,ROPStarvation介绍了近零(平均值0.2%)运行时性能开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号