Data Space Randomization

Data Space Randomization
复制标题

DOI:
10.1007/978-3-540-70542-0_1
复制
发表时间:
2008-07
影响因子:
--
通讯作者:
S. Bhatkar;R. Sekar
S. Bhatkar;R. Sekar
中科院分区:
--
文献类型:
--
作者:
S. Bhatkar;R. Sekar

文献摘要

被引文献

相似文献

在过去的几年里,US-CERT的建议,以及软件供应商的大多数关键更新,都是由于内存损坏漏洞,如缓冲区溢出、堆溢出等。已经开发了几种技术来防御对这些漏洞的利用,其中最有希望的防御是基于随机化的。到目前为止,已经探索了两种随机化技术:地址空间随机化(ASR)和指令集随机化(ISR)。地址空间随机化(ASR)使对象在虚拟内存中的位置随机化,指令集随机化(ISR)使代码表示随机化。我们探索了第三种形式的随机化,称为数据空间随机化(DSR),它随机化存储在程序内存中的数据的表示。与ISR不同,DSR对非控制数据攻击和代码注入攻击都很有效。与ASR不同,它可以防止非指针数据和指针值数据的损坏。此外,与ASR相比,DSR提供了更高的随机化范围(32位数据通常为232)。DSR的其他有趣方面包括(a)它不具有基于随机化的防御的共同弱点,即对信息泄漏攻击的易感性,以及(b)它能够检测到一些被全边界检查技术遗漏的漏洞,例如,从结构的一个字段到下一个字段的一些溢出。我们的实现结果表明,通过适当的设计选择,DSR可以在一系列程序中实现5%至30%的性能开销。
Over the past several years, US-CERT advisories, as well as most critical updates from software vendors, have been due to memory corruption vulnerabilities such as buffer overflows, heap overflows, etc. Several techniques have been developed to defend against the exploitation of these vulnerabilities, with the most promising defenses being based on randomization. Two randomization techniques have been explored so far: address space randomization (ASR) that randomizes the location of objects in virtual memory, and instruction set randomization (ISR) that randomizes the representation of code. We explore a third form of randomization called data space randomization (DSR) that randomizes the representation of data stored in program memory. Unlike ISR, DSR is effective against non-control data attacks as well as code injection attacks. Unlike ASR, it can protect against corruption of non-pointer data as well as pointer-valued data. Moreover, DSR provides a much higher range of randomization (typically 232for 32-bit data) as compared to ASR. Other interesting aspects of DSR include (a) it does not share a weakness common to randomization-based defenses, namely, susceptibility to information leakage attacks, and (b) it is capable of detecting some exploits that are missed by full bounds-checking techniques, e.g., some of the overflows from one field of a structure to the next field. Our implementation results show that with appropriate design choices, DSR can achieve a performance overhead in the range of 5% to 30% for a range of programs.