TRUVIN: Lightweight Detection of Data-Oriented Attacks Through Trusted Value Integrity

TRUVIN: Lightweight Detection of Data-Oriented Attacks Through Trusted Value Integrity
复制标题

TRUVIN:通过可信值完整性轻量级检测面向数据的攻击

DOI:
--
复制
发表时间:
2020
期刊:
International Conference on Trust, Security and Privacy in Computing and Communications
影响因子:
--
通讯作者:
Kasper Bonne Rasmussen
Kasper Bonne Rasmussen
中科院分区:
--
文献类型:
--
作者:
Munir Geden;Kasper Bonne Rasmussen

文献摘要

参考文献

相似文献

面向数据的攻击,即攻击者破坏内存中的关键程序数据,仍然是最具挑战性的安全威胁之一。由于攻击者不接触任何代码或代码指针,因此面向数据的攻击能够规避常见的防御策略,例如数据执行预防或控制流保护。数据流完整性(DFI)技术可以通过检测任何程序数据的损坏来减轻这些攻击。然而,由于高性能成本,这些技术在实践中没有被广泛采用。本文介绍了TRUVIN,一个轻量级的计划,解决面向数据的攻击,只关注那些变量的完整性保证是至关重要的。TRUVIN不是检查每个存储器操作,而是选择性地检测仅来自可信代理的程序数据(例如,程序员),因为它们被认为对运行时完整性至关重要。我们的计划分析的程序在编译时,并产生仪器只为必要的操作。TRUVIN将性能成本平均降低了4.3倍,与全仪表(121%)相比,开销降低了28%,同时保持了安全性保证。
Data-oriented attacks, where the adversary corrupts critical program data in memory, remain one of the most challenging security threats to address. Because the attacker does not touch any code or code pointers, data-oriented attacks are able to circumvent common defence strategies such as data execution prevention or control-flow protection. Dataflow integrity (DFI) techniques can mitigate these attacks by detecting corruption of any program data. However, due to high performance costs, these techniques are not widely adopted in practice. This paper presents TRUVIN, a lightweight scheme that addresses data-oriented attacks by focusing on only those variables which are crucial to the integrity assurance. Instead of checking every memory operation, TRUVIN selectively instruments program data originating from only trusted agents (e.g., the programmer), as they are considered critical to the runtime integrity. Our scheme analyses the program at compile time, and generates instrumentation only for the necessary operations. TRUVIN reduces the performance cost by a factor of 4.3 on average with 28% overhead compared to full instrumentation (121%), while retaining the security guarantees.
DOI: 10.1109/pst47121.2019.8949036
发表时间: 2019-08
期刊: 2019 17th International Conference on Privacy, Security and Trust (PST)
影响因子: --
作者:
Munir Geden;Kasper Bonne Rasmussen
通讯作者: Munir Geden;Kasper Bonne Rasmussen
DOI: 10.1145/3243734.3243739
发表时间: 2018-05
期刊: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer
通讯作者: Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer
DOI: 10.1109/sp40000.2020.00042
发表时间: 2018-02
期刊: 2020 IEEE Symposium on Security and Privacy (SP)
影响因子: --
作者:
Zhichuang Sun;Bo Feng;Long Lu;S. Jha
通讯作者: Zhichuang Sun;Bo Feng;Long Lu;S. Jha