No Free Lunch: On the Increased Code Reuse Attack Surface of Obfuscated Programs

No Free Lunch: On the Increased Code Reuse Attack Surface of Obfuscated Programs
复制标题

DOI:
10.1109/dsn58367.2023.00039
复制
发表时间:
2023-06
期刊:
2023 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
通讯作者:
Naiqian Zhang;Daroc Alden;Dongpeng Xu;Shuai Wang;T. Jaeger;Wheeler Ruml
Naiqian Zhang;Daroc Alden;Dongpeng Xu;Shuai Wang;T. Jaeger;Wheeler Ruml
中科院分区:
其他
文献类型:
--
作者:
Naiqian Zhang;Daroc Alden;Dongpeng Xu;Shuai Wang;T. Jaeger;Wheeler Ruml

文献摘要

相似文献

混淆已被广泛应用于保护软件免受恶意逆向分析。然而,其安全风险此前并未得到详细研究。例如,大多数混淆方法都会引入大块不透明代码,这些代码对于普通用户来说是黑匣子。在本文中,我们表明混淆确实会增加攻击风险。现有的小工具搜索工具虽然能够在混淆的代码中找到更多的小工具,但无法成功地将它们组装成更多的漏洞利用。然而,这些工具使用严格的模式匹配、贪婪搜索策略,并且仅使用非常简单的小工具。我们开发了 Gadget-Planner,这是一种更灵活的构建代码重用攻击的方法,通过符号执行和自动规划克服了以前的限制。在一项针对基准程序和实际程序的研究中,这种方法在混淆程序上发现了更多的利用有效负载,无论是数量还是多样性。
Obfuscation has been widely employed to protect software from the malicious reverse analysis. However, its security risks have not previously been studied in detail. For example, most obfuscation methods introduce large blocks of opaque code that are black boxes to normal users. In this paper, we show that, indeed, obfuscation can increase the attack risk. Existing gadget search tools, while able to find more gadgets in obfuscated code, do not succeed in assembling them into more exploits. However, these tools use strict pattern matching, greedy searching strategies, and only very simple gadgets. We develop Gadget-Planner, a more flexible approach to building code-reuse attacks that overcomes previous limitations via symbolic execution and automated planning. In a study across both benchmark and real-world programs, this approach finds many more exploit payloads on obfuscated programs, both in terms of number and diversity.