Block Oriented Programming: Automating Data-Only Attacks

Block Oriented Programming: Automating Data-Only Attacks
复制标题

DOI:
10.1145/3243734.3243739
复制
发表时间:
2018-05
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer
Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer
中科院分区:
其他
文献类型:
--
作者:
Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer

文献摘要

被引文献

相似文献

随着控制流完整性(CFI)的广泛应用,控制流劫持攻击以及随之而来的代码复用攻击变得更加困难。CFI将控制流限制在已知位置,严重限制了任意代码的执行。在诸如CFI和影子栈等高级控制流劫持防御措施下评估应用程序剩余的攻击面仍然是一个未解决的问题。我们引入了BOPC,这是一种自动评估攻击者是否能够在采用CFI/影子栈防御加固的二进制文件上执行任意代码的机制。BOPC根据用一种图灵完备的高级语言(称为SPL,它抽象出架构和特定于程序的细节)编写的有效载荷规范为目标程序计算漏洞利用。SPL有效载荷被编译成一个程序跟踪,在目标二进制文件上执行所需的行为。BOPC的输入是一个SPL有效载荷、一个起始点(例如,来自模糊测试器崩溃)以及一个允许应用程序状态损坏的任意内存写入原语。为了将SPL有效载荷映射到程序跟踪,BOPC引入了面向块编程(BOP),这是一种新的代码复用技术,它沿着程序中的有效执行路径将整个基本块用作小工具,即不违反CFI或影子栈策略。我们发现将有效载荷映射到程序跟踪的问题是NP难的,因此BOPC首先通过修剪不可行路径来减少搜索空间,然后使用启发式方法引导搜索到可能的路径。BOPC将BOP有效载荷编码为一组内存写入。我们对10个流行应用程序执行了13个SPL有效载荷。BOPC在81%的情况下,在理想的CFI策略下遵循目标的控制流图时,成功地找到了有效载荷和复杂的执行跟踪——这些很可能通过手动分析无法找到。
With the widespread deployment of Control-Flow Integrity (CFI), control-flow hijacking attacks, and consequently code reuse attacks, are significantly more difficult. CFI limits control flow to well-known locations, severely restricting arbitrary code execution. Assessing the remaining attack surface of an application under advanced control-flow hijack defenses such as CFI and shadow stacks remains an open problem. We introduce BOPC, a mechanism to automatically assess whether an attacker can execute arbitrary code on a binary hardened with CFI/shadow stack defenses. BOPC computes exploits for a target program from payload specifications written in a Turing-complete, high-level language called SPL that abstracts away architecture and program-specific details. SPL payloads are compiled into a program trace that executes the desired behavior on top of the target binary. The input for BOPC is an SPL payload, a starting point (e.g., from a fuzzer crash) and an arbitrary memory write primitive that allows application state corruption. To map SPL payloads to a program trace, BOPC introduces Block Oriented Programming (BOP), a new code reuse technique that utilizes entire basic blocks as gadgets along valid execution paths in the program, i.e., without violating CFI or shadow stack policies. We find that the problem of mapping payloads to program traces is NP-hard, so BOPC first reduces the search space by pruning infeasible paths and then uses heuristics to guide the search to probable paths. BOPC encodes the BOP payload as a set of memory writes. We execute 13 SPL payloads applied to 10 popular applications. BOPC successfully finds payloads and complex execution traces -- which would likely not have been found through manual analysis -- while following the target's Control-Flow Graph under an ideal CFI policy in 81% of the cases.