Sleak: automating address space layout derandomization

Sleak: automating address space layout derandomization
复制标题

Sleak:自动化地址空间布局去随机化

DOI:
10.1145/3359789.3359820
复制
发表时间:
2019
期刊:
Proceedings of the 35th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Kruegel, Christopher
Kruegel, Christopher
中科院分区:
--
文献类型:
--
作者:
Hauser, Christophe;Menon, Jayakrishna;Shoshitaishvili, Yan;Wang, Ruoyu;Vigna, Giovanni;Kruegel, Christopher

文献摘要

参考文献

相似文献

我们提出了一种新颖的方法,可以在存在地址空间布局随机化(ASLR)的情况下自动恢复有关远程进程的地址空间布局的信息。我们的系统,称为Sleak,对二进制可执行程序进行静态分析和符号执行,并识别导致部分(即只有几个位)或完整(即整个地址)信息泄露漏洞的程序路径和输入参数,从而泄露目标服务或应用程序的已知对象的地址。Sleak将二进制可执行程序作为输入,并生成非符号 每个程序输出的表达式都会泄漏有关对象地址的信息,例如堆栈变量、堆结构或函数指针。通过将这些表达式与执行相同二进制程序映像的远程进程的具体输出进行比较,我们的系统能够恢复目标应用程序或服务的对象的几个位地址到整个地址。发现目标应用程序中单个对象的地址通常足以猜测地址空间的整个部分的布局,攻击者可以利用它来绕过 ASLR。
We present a novel approach to automatically recover information about the address space layout of remote processes in the presence of Address Space Layout Randomization (ASLR). Our system, dubbedSleak, performs static analysis and symbolic execution of binary executable programs, and identifies program paths and input parameters leading topartial(i.e., only a few bits) orcomplete(i.e., the whole address) information disclosure vulnerabilities, revealing addresses of known objects of the target service or application.Sleaktakes, as input, the binary executable program, and generates asymbolic expressionfor each program output that leaks information about the addresses of objects, such as stack variables, heap structures, or function pointers. By comparing these expressions with the concrete output of a remote process executing the same binary program image, our system is able to recover from a few bits to whole addresses of objects of the target application or service. Discovering the address of a single object in the target application is often enough to guess the layout of entire sections of the address space, which can be leveraged by attackers to bypass ASLR.
BootStomp:论移动设备中引导加载程序的安全性
DOI: --
发表时间: 2017
期刊: USENIX Security Symposium
影响因子: --
作者:
Nilo Redini;Aravind Machiry;Dipanjan Das;Y. Fratantonio;Antonio Bianchi;Eric Gustafson;Yan Shoshitaishvili;Christopher Krügel;Giovanni Vigna
通讯作者: Giovanni Vigna
DOI: 10.1145/1315245.1315313
发表时间: 2007-10
期刊: --
影响因子: --
作者:
H. Shacham
通讯作者: H. Shacham
检测基于堆栈的内核信息泄漏
DOI: --
发表时间: 2014
期刊: International Conference on European Transnational Education
影响因子: --
作者:
S. Peiró;Manuel Muñoz;M. Masmano;A. Crespo
通讯作者: A. Crespo
DOI: --
发表时间: 1958
期刊:
影响因子: --
作者:
F. RenshawEdward
通讯作者: F. RenshawEdward
DOI: --
发表时间: 2016-03
影响因子: 3.3
作者:
Hector Marco Gisbert;I. Ripoll
通讯作者: Hector Marco Gisbert;I. Ripoll