Rave: A Modular and Extensible Framework for Program State Re-Randomization
Rave: A Modular and Extensible Framework for Program State Re-Randomization
复制标题
Rave:用于程序状态重新随机化的模块化且可扩展的框架
DOI:
10.1145/3560828.3564008
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Ravindran, Binoy
中科院分区:
文献类型:
--
作者:
Blackburn, Christopher;Wang, Xiaoguang;Ravindran, Binoy
Dynamic software diversification is an effective way to boost software security. Existing diversification-based approaches often target a single node environment and leverage in-process agents to diversify code and data, resulting in an unnecessary attack surface on a fixed software/hardware stack. This paper presentsRave, a practical system designed to enable out-of-bound program state shuffling on a moving target environment, avoiding any sensitive agent code invoked within the running target.Raverelies on a user-space page fault handling mechanism introduced in the latest Linux kernel and seamlessly integrates with CRIU, the battle-tested process migration tool for Linux.Raveconsists of two components: librave, a library for static binary analysis and instrumentation, and CRIU-Rave, a runtime that dynamically updates program execution states (e.g., internal stack data layout and the machine node the program runs on). We built a prototype of Rave and evaluated it with four real-world server applications and 13 applications from the SPEC CPU 2017 and the SNU C version of NAS Parallel Benchmarks (NPB) benchmark suites. We demonstrated thatRavecan continuously re-randomize the program state (e.g., internal stack layout, instruction sequences, and machine node to run on). The evaluation shows thatRaveincreases the internal program state entropy with an additional ≈200 ms time overhead for each re-randomization epoch on average.
登录
查看更多内容
影响因子:
2
作者:
Sylvain Firer-Blaess;C. Fuchs
通讯作者:
Sylvain Firer-Blaess;C. Fuchs
影响因子:
--
作者:
S. Bhatkar;R. Sekar
通讯作者:
S. Bhatkar;R. Sekar
DOI:
10.1145/3243734.3243739
发表时间:
2018-05
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer
通讯作者:
Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer
DOI:
10.1109/hase.2016.27
发表时间:
2016
期刊:
2016 IEEE 17th International Symposium on High Assurance Systems Engineering (HASE)
影响因子:
--
作者:
Yufei Jiang;Can Zhang;Dinghao Wu;Peng Liu
通讯作者:
Peng Liu