Rave: A Modular and Extensible Framework for Program State Re-Randomization

Rave: A Modular and Extensible Framework for Program State Re-Randomization
复制标题

Rave:用于程序状态重新随机化的模块化且可扩展的框架

DOI:
10.1145/3560828.3564008
复制
发表时间:
2022
期刊:
Proceedings of the 9th ACM Workshop on Moving Target Defense
影响因子:
--
通讯作者:
Ravindran, Binoy
Ravindran, Binoy
中科院分区:
--
文献类型:
--
作者:
Blackburn, Christopher;Wang, Xiaoguang;Ravindran, Binoy

文献摘要

参考文献

被引文献

相似文献

动态软件多样化是提高软件安全性的有效途径。现有的基于多样化的方法通常针对单节点环境,并利用进程内代理来使代码和数据多样化,从而导致固定软件/硬件堆栈上出现不必要的攻击面。本文介绍了 Rave,一个实用的系统,旨在在移动目标环境中实现出界程序状态改组,避免在运行目标中调用任何敏感代理代码。Rave 依赖于最新 Linux 内核中引入的用户空间页面错误处理机制,并与久经考验的 Linux 进程迁移工具 CRIU 无缝集成。Rave 由两个组件组成:librave(用于静态二进制分析和检测的库)和 CRIU-Rave(动态更新程序执行状态的运行时) (例如,内部堆栈数据布局和程序运行的机器节点)。我们构建了 Rave 原型,并使用来自 SPEC CPU 2017 和 SNU C 版本 NAS 并行基准 (NPB) 基准套件的 4 个实际服务器应用程序和 13 个应用程序对其进行了评估。我们证明了 Rave 可以不断地重新随机化程序状态(例如,内部堆栈布局、指令序列和要运行的机器节点)。评估表明,Rave 增加了内部程序状态熵,平均每个重新随机化周期额外增加了约 200 毫秒的时间开销。
Dynamic software diversification is an effective way to boost software security. Existing diversification-based approaches often target a single node environment and leverage in-process agents to diversify code and data, resulting in an unnecessary attack surface on a fixed software/hardware stack. This paper presentsRave, a practical system designed to enable out-of-bound program state shuffling on a moving target environment, avoiding any sensitive agent code invoked within the running target.Raverelies on a user-space page fault handling mechanism introduced in the latest Linux kernel and seamlessly integrates with CRIU, the battle-tested process migration tool for Linux.Raveconsists of two components: librave, a library for static binary analysis and instrumentation, and CRIU-Rave, a runtime that dynamically updates program execution states (e.g., internal stack data layout and the machine node the program runs on). We built a prototype of Rave and evaluated it with four real-world server applications and 13 applications from the SPEC CPU 2017 and the SNU C version of NAS Parallel Benchmarks (NPB) benchmark suites. We demonstrated thatRavecan continuously re-randomize the program state (e.g., internal stack layout, instruction sequences, and machine node to run on). The evaluation shows thatRaveincreases the internal program state entropy with an additional ≈200 ms time overhead for each re-randomization epoch on average.
DOI: 10.1177/1527476412450193
发表时间: 2014-02
影响因子: 2
作者:
Sylvain Firer-Blaess;C. Fuchs
通讯作者: Sylvain Firer-Blaess;C. Fuchs
DOI: 10.1007/978-3-540-70542-0_1
发表时间: 2008-07
影响因子: --
作者:
S. Bhatkar;R. Sekar
通讯作者: S. Bhatkar;R. Sekar
DOI: 10.1145/3243734.3243739
发表时间: 2018-05
期刊: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer
通讯作者: Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer
基于特征的软件定制:初步分析、形式化和方法
DOI: 10.1109/hase.2016.27
发表时间: 2016
期刊: 2016 IEEE 17th International Symposium on High Assurance Systems Engineering (HASE)
影响因子: --
作者:
Yufei Jiang;Can Zhang;Dinghao Wu;Peng Liu
通讯作者: Peng Liu