Methodologies for Quantifying (Re-)randomization Security and Timing under JIT-ROP
Methodologies for Quantifying (Re-)randomization Security and Timing under JIT-ROP
复制标题
JIT-ROP 下量化(重新)随机化安全性和计时的方法
DOI:
10.1145/3372297
复制
发表时间:
2020
期刊:
影响因子:
--
通讯作者:
Salman Ahmed, Ya Xiao
中科院分区:
文献类型:
--
作者:
Salman Ahmed, Ya Xiao
Just-in-time return-oriented programming (JIT-ROP) allows one to dynamically discover instruction pages and launch code reuse attacks, effectively bypassing most fine-grained address space layout randomization (ASLR) protection. However, in-depth questions regarding the impact of code (re-)randomization on code reuse attacks have not been studied. For example, how would one compute the re-randomization interval effectively by considering the speed of gadget convergence to defeat JIT-ROP attacks? ; how do starting pointers in JIT-ROP impact gadget availability and gadget convergence time? ; what impact do fine-grained code randomizations have on the Turing-complete expressive power of JIT-ROP payloads? We conduct a comprehensive measurement study on the effectiveness of fine-grained code randomization schemes, with 5 tools, 20 applications including 6 browsers, 1 browser engine, and 25 dynamic libraries. We provide methodologies to measure JIT-ROP gadget availability, quality, and their Turing-complete expressiveness, as well as to empirically determine the upper bound of re-randomization intervals in re-randomization schemes using the Turing-complete (TC), priority, MOV TC, and payload gadget sets. Experiments show that the upper bound ranges from 1.5 to 3.5 seconds in our tested applications. Besides, our results show that locations of leaked pointers used in JIT-ROP attacks have no impacts on gadget availability but have an impact on how fast attackers find gadgets. Our results also show that instruction-level single-round randomization thwarts current gadget finding techniques under the JIT-ROP threat model.
登录
查看更多内容
DOI:
10.1145/1315245.1315313
发表时间:
2007-10
期刊:
--
影响因子:
--
作者:
H. Shacham
通讯作者:
H. Shacham
DOI:
10.1145/3243734.3243739
发表时间:
2018-05
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer
通讯作者:
Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer
DOI:
10.14722/ndss.2015.23248
发表时间:
2015
期刊:
--
影响因子:
--
作者:
X. Chen;Asia Slowinska;Dennis Andriesse;H. Bos;Cristiano Giuffrida
通讯作者:
X. Chen;Asia Slowinska;Dennis Andriesse;H. Bos;Cristiano Giuffrida
DOI:
10.1007/978-3-319-11379-1_5
发表时间:
2014-09
期刊:
--
影响因子:
--
作者:
Felix Schuster;Thomas Tendyck;Jannik Pewny;A. Maaß;Martin Steegmanns;Moritz Contag;Thorsten Holz
通讯作者:
Felix Schuster;Thomas Tendyck;Jannik Pewny;A. Maaß;Martin Steegmanns;Moritz Contag;Thorsten Holz
DOI:
10.1145/2660267.2660378
发表时间:
2014-11
期刊:
Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
M. Backes;Thorsten Holz;B. Kollenda;Philipp Koppe;S. Nürnberger;Jannik Pewny
通讯作者:
M. Backes;Thorsten Holz;B. Kollenda;Philipp Koppe;S. Nürnberger;Jannik Pewny