Exploiting Linux and PaX ASLR’s weaknesses on 32-bit and 64-bit systems

Exploiting Linux and PaX ASLR’s weaknesses on 32-bit and 64-bit systems
复制标题

DOI:
--
复制
发表时间:
2016-03
影响因子:
3.3
通讯作者:
Hector Marco Gisbert;I. Ripoll
Hector Marco Gisbert;I. Ripoll
中科院分区:
医学4区
文献类型:
--
作者:
Hector Marco Gisbert;I. Ripoll

文献摘要

被引文献

相似文献

地址空间布局随机化是一种非常有效的缓解技术。PaX团队在2001年完成了第一个实现,从那时起,它一直是最先进和最安全的。我们分析了PaX和Linux的实现,发现了几个弱点。我们对决定ASLR运行的所有限制因素进行了深入的审查和分析。基于这些结果,我们设计并实现了一种新的ASLR称为ASLR-NG,它最大限度地提高了熵(安全性),不引入碎片(兼容性)。ASLR-NG特别适用于32位系统,因为其固有的VMA大小减小。我们开发了ASLRA,一个分析ASLR质量的工具。该工具显示ASLR-NG在各个方面都优于PaX ASLR。
Address Space Layout Randomization is a very effective mitigation technique. The first implementation was done by the PaX team in 2001, and since then it has been the most advanced and secure. We have analyzed the PaX an Linux implementations, and found several weaknesses. We have carried out a deep review and analysis of all constraints that determine ASLR operation. Based on these results we have designed and implemented a novel ASLR called ASLR-NG, which maximized the entropy (security) and does not introduce fragmentation (compatibility). ASLR-NG is specially suitable for 32-bit systems because of their intrinsic reduced VMA size. We have developed ASLRA, a tool to analyze the quality of the ASLR. This tool shows that ASLR-NG outperforms PaX ASLR in all aspects.