Security Analysis of Processor Instruction Set Architecture for Enforcing Control-Flow Integrity

Security Analysis of Processor Instruction Set Architecture for Enforcing Control-Flow Integrity
复制标题

用于加强控制流完整性的处理器指令集架构的安全分析

DOI:
--
复制
发表时间:
2019
期刊:
HASP@ISCA
影响因子:
--
通讯作者:
R. Sahita
R. Sahita
中科院分区:
--
文献类型:
--
作者:
Vedvyas Shanbhogue;D. Gupta;R. Sahita

文献摘要

被引文献

相似文献

英特尔已经开发了控制流动执法技术(CET)[27],它提供了CPU指令集架构(ISA)功能,以防止以返回为导向的编程(ROP)和CALL/JMP面向COP/JMP的编程(COP/JOP)风格控制 - 风格控制权。颠覆攻击。此攻击方法使用授权模块中的代码序列,该序列中至少有一项指令是控制转移指令,该指令依赖于返回堆栈中的攻击者控制的数据或目标地址的寄存器/内存中。攻击者通过将控制流指令(例如RET,呼叫,JMP)从其原始目标地址转移到新目标(通过数据堆中的修改或这些说明使用的寄存器或内存中的修改)将这些序列缝合在一起。本文介绍了CET安全目标,威胁模型和各种架构设计选择,以确保设计符合安全目标。我们在该领域的性能数据和相关工作结束了论文。
Intel has developed Control-flow Enforcement Technology (CET) [27] that provides CPU instruction set architecture (ISA) capabilities to defend against Return-oriented Programming (ROP) and call/jmp-oriented programming (COP/JOP) style control-flow subversion attacks. This attack methodology uses code sequences in authorized modules with at least one instruction in the sequence being a control transfer instruction that depends on attacker-controlled data either in the return stack or in a register/memory for the target address. Attackers stitch these sequences together by diverting the control flow instruction (e.g. RET, CALL, JMP) from its original target address to a new target (via modification in the data stack or in the register or memory used by these instructions). This paper describes CET security objectives, threat model and various architectural design choices to ensure that the design meets the security objectives. We conclude the paper with performance data and related work in this domain.