You Can Run but You Can't Read: Preventing Disclosure Exploits in Executable Code

You Can Run but You Can't Read: Preventing Disclosure Exploits in Executable Code
复制标题

DOI:
10.1145/2660267.2660378
复制
发表时间:
2014-11
期刊:
Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
M. Backes;Thorsten Holz;B. Kollenda;Philipp Koppe;S. Nürnberger;Jannik Pewny
M. Backes;Thorsten Holz;B. Kollenda;Philipp Koppe;S. Nürnberger;Jannik Pewny
中科院分区:
其他
文献类型:
--
作者:
M. Backes;Thorsten Holz;B. Kollenda;Philipp Koppe;S. Nürnberger;Jannik Pewny

文献摘要

被引文献

相似文献

代码重用攻击允许攻击者对原本良性的程序施加恶意行为。为了减轻这种攻击,一种常见的方法是通过随机化或重写来掩盖代码片段的地址或内容,让攻击者别无选择,只能猜测。然而,公开攻击允许攻击者扫描进程——甚至远程扫描——并使其能够实时读取可执行内存,从而允许在目标站点上及时组装漏洞。在本文中,我们提出了一种方法,通过防止在代码本身仍然可以执行时无意地读取代码,从根本上阻止内存披露漏洞的根源。我们引入了一个新的原语,我们称之为Execute-no-Read (XnR),它确保代码仍然可以被处理器执行,但同时代码不能作为数据被读取。这最终丧失了即时代码重用攻击(JIT-ROP)所必需的自反汇编功能。据我们所知,XnR是防止可执行代码的内存泄露攻击和JIT-ROP攻击的第一种方法。尽管在当代Intel x86和ARM处理器中缺乏对XnR的硬件支持,但我们针对Linux和Windows的软件模拟的运行时开销分别只有2.2%和3.4%。
Code reuse attacks allow an adversary to impose malicious behavior on an otherwise benign program. To mitigate such attacks, a common approach is to disguise the address or content of code snippets by means of randomization or rewriting, leaving the adversary with no choice but guessing. However, disclosure attacks allow an adversary to scan a process - even remotely - and enable her to read executable memory on-the-fly, thereby allowing the just-in time assembly of exploits on the target site. In this paper, we propose an approach that fundamentally thwarts the root cause of memory disclosure exploits by preventing the inadvertent reading of code while the code itself can still be executed. We introduce a new primitive we call Execute-no-Read (XnR) which ensures that code can still be executed by the processor, but at the same time code cannot be read as data. This ultimately forfeits the self-disassembly which is necessary for just-in-time code reuse attacks (JIT-ROP) to work. To the best of our knowledge, XnR is the first approach to prevent memory disclosure attacks of executable code and JIT-ROP attacks in general. Despite the lack of hardware support for XnR in contemporary Intel x86 and ARM processors, our software emulations for Linux and Windows have a run-time overhead of only 2.2% and 3.4%, respectively.