The Continuing Arms Race: Code-Reuse Attacks and Defenses

The Continuing Arms Race: Code-Reuse Attacks and Defenses
复制标题

持续的军备竞赛:代码重用攻击和防御

DOI:
10.1145/3129743
复制
发表时间:
2018
期刊:
The Continuing Arms Race
影响因子:
--
通讯作者:
A. Sadeghi
A. Sadeghi
中科院分区:
--
文献类型:
--
作者:
Per Larsen;A. Sadeghi

文献摘要

被引文献

相似文献

随着人类活动向数字领域转移,所有众所周知的恶意行为也随之转移,包括欺诈、盗窃和其他诡计。没有灵丹妙药,每个安全威胁都需要一个具体的答案。一个特别的威胁是,应用程序接受格式错误的输入,在许多情况下,可以手工创建输入,让入侵者完全控制目标计算机系统。 系统编程语言的本质是问题的核心。这本书没有重写几十年来经过良好测试的功能,而是研究了如何在以尽可能最有效的方式支撑安全性的同时,与过去的(编程)罪恶共存。我们探索了一系列不同的选项,每个选项都在保护遗留程序免受恶意输入方面取得了重大进展。 探索的解决方案包括强制类型的防御,它排除了某些程序执行,因为它们在正常操作期间不会出现。另一条线索探索了向对手呈现一个移动目标的想法,由于随机化,该目标不可预测地改变了攻击面。我们还讨论了串联执行的想法,其中一个执行克隆的妥协导致它与另一个克隆分离,从而揭示了敌对活动。
As human activities have moved to the digital domain, so have all the well-known malicious behaviors including fraud, theft, and other trickery. There is no silver bullet, and each security threat calls for a specific answer. One particular threat is that applications accept malformed inputs, and in many cases it is possible to craft inputs that let an intruder take full control over the target computer system. The nature of systems programming languages lies at the heart of the problem. Rather than rewriting decades of well-tested functionality, this book examines ways to live with the (programming) sins of the past while shoring up security in the most efficient manner possible. We explore a range of different options, each making significant progress toward securing legacy programs from malicious inputs. The solutions explored include enforcement-type defenses, which exclude certain program executions because they never arise during normal operation. Another strand explores the idea of presenting adversaries with a moving target that unpredictably changes its attack surface thanks to randomization. We also cover tandem execution ideas where the compromise of one executing clone causes it to diverge from another, thus revealing adversarial activities.