首页> 外文期刊>IEEE Transactions on Computers >Random CFI (RCFI): Efficient Fine-Grained Control-Flow Integrity Through Random Verification
【24h】

Random CFI (RCFI): Efficient Fine-Grained Control-Flow Integrity Through Random Verification

机译:随机CFI(RCFI):通过随机验证有效的细粒度控制流程完整性

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

In theory, Control-Flow Integrity (CFI) is considered a principled solution against control-data attacks. However, most fine-grained CFI schemes that ensure such high security suffer from significant performance overhead. Existing practical implementations have been proposed to overcome this performance overhead problem, but they have proven unable to guarantee high security because development of these implementations has focused on only improving performance, at the expense of the security guarantee. Even though it is important for CFI schemes to provide both high security and low performance overhead, existing research on CFI is limited either by way of performance or security guarantee. We propose a new approach of verification method in fine-grained CFI to achieve these two goals. Our scheme performs selective and random verifications for certain branches rather than all branches, and thus, can reduce performance overhead. We show improved performance by evaluating our proof-of-concept implementation on SPEC CPU 2017. In addition, we also show that our scheme does not significantly sacrifice the security guarantee of fine-grained CFI by analyzing the structure of existing control-data attack exploits, which were collected from real-world exploits DB and related literature.
机译:在理论上,控制流程完整性(CFI)被认为是针对控制数据攻击的原则性解决方案。然而,最细粒度的CFI方案,确保这种高安全性遭受显着的性能开销。已经提出了现有的实际实现来克服这种性能的开销问题,但由于这些实施的发展,他们已经证明无法保证高安全性,以牺牲安全保障的牺牲仅限于绩效。尽管CFI方案很重要,但提供高安全性和低性能开销,但通过性能或安全保证,现有的CFI研究是有限的。我们提出了一种在细粒度CFI中验证方法的新方法,以实现这两个目标。我们的方案对某些分支执行选择性和随机验证而不是所有分支机构,因此可以降低性能开销。我们通过评估2017年规范CPU的概念证明实施来表明,我们还表明,我们的计划通过分析现有控制数据攻击漏洞的结构,我们的计划不会显着牺牲细粒度CFI的安全保障,从真实世界的利用数据库和相关文献中收集。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号