Making Information Hiding Effective Again

Making Information Hiding Effective Again
复制标题

让信息隐藏再次有效

DOI:
10.1109/tdsc.2021.3064086
复制
发表时间:
2021
期刊:
IEEE Transactions on Dependable and Secure Computing (TDSC'21)
影响因子:
--
通讯作者:
Zhiping Shi
Zhiping Shi
中科院分区:
其他
文献类型:
--
作者:
Zhe Wang;Chenggang Wu;Yinqian Zhang;Bowen Tang;Pen-Chung Yew;Mengyao Xie;Yuanming Lai;Yan Kang;Yueqiang Cheng;Zhiping Shi

文献摘要

相似文献

信息隐藏(IH)由于其有效性和性能,是抵御代码重用攻击的重要组成部分,如代码指针完整性(CPI)、控制流完整性(CFI)和细粒度代码随机化(re- randomization)。它使用随机化来概率地“隐藏”敏感的内存区域,称为安全区,以防止攻击者,并确保它们的地址不会被任何指针直接泄露。这些防御使用安全区域来保护他们的关键数据,如跳跃目标和随机化秘密。然而,最近的研究表明,IH很容易受到各种攻击。在本文中,我们提出了一种新的IH技术,称为SafeHidden。它不断地重新随机化安全区域的位置,从而防止攻击者探测和推断内存布局以找到其位置。提出了一种新的线程私有内存机制来隔离线程本地安全区域,防止对手降低随机化熵。同时对TLB未命中后的安全区域进行随机化处理,防止攻击者利用缓存侧通道推断出安全区域的地址。现有的基于h的防御可以直接使用SafeHidden而无需任何更改。实验结果表明,该算法不仅有效地阻止了现有的攻击,而且性能开销很小。
Information hiding (IH) is an important building block for many defenses against code reuse attacks, such as code-pointer integrity (CPI), control-flow integrity (CFI) and fine-grained code (re-)randomization, because of its effectiveness and performance. It employs randomization to probabilistically “hide” sensitive memory areas, called safe areas, from attackers and ensures their addresses are not leaked by any pointers directly. These defenses used safe areas to protect their critical data, such as jump targets and randomization secrets. However, recent works have shown that IH is vulnerable to various attacks. In this article, we propose a new IH technique called SafeHidden. It continuously re-randomizes the locations of safe areas and thus prevents the attackers from probing and inferring the memory layout to find its location. A new thread-private memory mechanism is proposed to isolate the thread-local safe areas and prevent adversaries from reducing the randomization entropy. It also randomizes the safe areas after the TLB misses to prevent attackers from inferring the address of safe areas using cache side-channels. Existing IH-based defenses can utilize SafeHidden directly without any change. Our experiments show that SafeHidden not only prevents existing attacks effectively but also incurs low performance overhead.