Buffer overflow attack with multiple fault injection and a proven countermeasure

Buffer overflow attack with multiple fault injection and a proven countermeasure
复制标题

具有多重故障注入的缓冲区溢出攻击和经过验证的对策

DOI:
10.1007/s13389-016-0136-3
复制
发表时间:
2017
影响因子:
1.9
通讯作者:
Takafumi Aoki
Takafumi Aoki
中科院分区:
计算机科学4区
文献类型:
--
作者:
Shoei Nashimoto;Naofumi Homma;Yu-ichi Hayashi;Junko Takahashi;Hitoshi Fuji;Takafumi Aoki

文献摘要

参考文献

被引文献

相似文献

在本文中,我们提出了一种硬件/软件联合攻击来劫持微控制器上的程序流。其基本思想是利用微控制器中的多个故障注入配合软件攻击跳过几条指令。我们关注的是缓冲区溢出(BOF)攻击以及这种多重故障注入。所提出的攻击可以应用于具有针对BOF攻击的典型软件对策的程序代码。攻击通过跳过与对策相关的特定指令来操纵程序控制流,从而在微控制器上成功执行后续的BOF攻击代码。我们通过使用8位AVR ATmega163微控制器和32位ARM Cortex-M0+微控制器的实验证明了我们提出的攻击的有效性,其中目标软件配备了限制用户输入大小的对策来抵御BOF攻击。结果表明,我们的攻击可以覆盖堆栈中存储的返回地址,并调用任意恶意函数。我们还提出了一种针对我们的攻击的软件对策,并通过检查所有可能的指令跳过来证明其有效性。
In this paper, we present a hardware/software co-attack to hijack a program flow on microcontrollers. The basic idea is to skip a few instructions using multiple fault injection in microcontrollers in cooperation with a software attack. We focus on buffer overflow (BOF) attacks together with such multiple fault injection. The proposed attack can be applied to a program code with a typical software countermeasure against BOF attacks. The attack manipulates the program control flow by skipping specific instructions related to the countermeasure, and thus, the subsequent BOF attack code is successfully executed on the microcontroller. We show the effectiveness of our proposed attack through experiments using an 8-bit AVR ATmega163 microcontroller and a 32-bit ARM Cortex-M0+ microcontroller, where the target software was equipped with a countermeasure limiting the size of user input against BOF attacks. The result showed that our attack can overwrite a return address stored in a stack and call an arbitrary malicious function. We also propose a software countermeasure against our attack and prove its validity by examining all the possible instruction skips.
使用故障来实现缓冲区溢出效果
DOI: 10.1145/2245276.2232038
发表时间: 2012
期刊: --
影响因子: --
作者:
Pierre;Delphine Leresteux;F. Valette
通讯作者: F. Valette
用于故障注入实验的可配置片上毛刺时钟发生器
DOI: 10.1587/transfun.e95.a.263
发表时间: 2012
期刊: IEICE Trans. Fundam. Electron. Commun. Comput. Sci.
影响因子: --
作者:
S. Endo;T. Sugawara;N. Homma;T. Aoki;Akashi Satoh
通讯作者: Akashi Satoh
DOI: 10.1007/978-3-642-12510-2_11
发表时间: 2010
期刊: 2011 IEEE International Workshop on Information Forensics and Security
影响因子: --
作者:
G. Barbu;Hugues Thiebeauld;Vincent Guerin
通讯作者: Vincent Guerin