Morpheus: A Vulnerability-Tolerant Secure Architecture Based on Ensembles of Moving Target Defenses with Churn

Morpheus: A Vulnerability-Tolerant Secure Architecture Based on Ensembles of Moving Target Defenses with Churn
复制标题

DOI:
10.1145/3297858.3304037
复制
发表时间:
2019-04
期刊:
Proceedings of the Twenty-Fourth International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子:
--
通讯作者:
Mark Gallagher;Lauren Biernacki;Shibo Chen;Zelalem Birhanu Aweke;Salessawi Ferede Yitbarek;Misiker Tadesse Aga;Austin Harris;Zhixing Xu;Baris Kasikci;V. Bertacco;S. Malik;Mohit Tiwari;T. Austin
Mark Gallagher;Lauren Biernacki;Shibo Chen;Zelalem Birhanu Aweke;Salessawi Ferede Yitbarek;Misiker Tadesse Aga;Austin Harris;Zhixing Xu;Baris Kasikci;V. Bertacco;S. Malik;Mohit Tiwari;T. Austin
中科院分区:
其他
文献类型:
--
作者:
Mark Gallagher;Lauren Biernacki;Shibo Chen;Zelalem Birhanu Aweke;Salessawi Ferede Yitbarek;Misiker Tadesse Aga;Austin Harris;Zhixing Xu;Baris Kasikci;V. Bertacco;S. Malik;Mohit Tiwari;T. Austin

文献摘要

被引文献

相似文献

攻击通常通过滥用程序和机器级语义之间的差距而成功--例如,通过定位敏感指针、利用错误来覆盖该敏感数据,以及劫持受害程序的执行。在这项工作中,我们通过不断混淆攻击者需要但正常程序不使用的信息,例如代码和指针的表示或代码和数据的确切位置,来进行安全系统设计。我们的安全硬件架构,Morpheus,结合了两个强大的保护:移动目标防御和搅动。移动目标防御的集合将关键程序值随机化(例如,重新定位指针和加密代码和指针),从而迫使攻击者在攻击之前广泛探查系统。为了确保攻击探测失败,该体系结构结合了FUSUN,以透明地重新随机化运行系统下的程序值。随着频繁的变动,系统很快就变得不切实际地难以渗透。我们通过一个基于RISC-V的原型演示了Morpheus,该原型旨在阻止控制流攻击。Morpheus中的每个移动目标防御都使用硬件支持,以比以前的技术更低的成本单独提供更多的随机性。当与Churn集成时,Morpheus防御系统可提供针对控制流攻击的强大保护,我们的安全测试和性能研究揭示:i)对广泛的控制流攻击的高覆盖保护,包括对高级攻击和Morpheus设计后披露的攻击的保护,以及ii)可以忽略不计的性能影响(1%),Churn周期长达50 ms,我们的研究估计这至少比渗透Morpheus所需的时间快5000倍。
Attacks often succeed by abusing the gap between program and machine-level semantics-- for example, by locating a sensitive pointer, exploiting a bug to overwrite this sensitive data, and hijacking the victim program's execution. In this work, we take secure system design on the offensive by continuously obfuscating information that attackers need but normal programs do not use, such as representation of code and pointers or the exact location of code and data. Our secure hardware architecture, Morpheus, combines two powerful protections: ensembles of moving target defenses and churn. Ensembles of moving target defenses randomize key program values (e.g., relocating pointers and encrypting code and pointers) which forces attackers to extensively probe the system prior to an attack. To ensure attack probes fail, the architecture incorporates churn to transparently re-randomize program values underneath the running system. With frequent churn, systems quickly become impractically difficult to penetrate. We demonstrate Morpheus through a RISC-V-based prototype designed to stop control-flow attacks. Each moving target defense in Morpheus uses hardware support to individually offer more randomness at a lower cost than previous techniques. When ensembled with churn, Morpheus defenses offer strong protection against control-flow attacks, with our security testing and performance studies revealing: i) high-coverage protection for a broad array of control-flow attacks, including protections for advanced attacks and an attack disclosed after the design of Morpheus, and ii) negligible performance impacts (1%) with churn periods up to 50 ms, which our study estimates to be at least 5000x faster than the time necessary to possibly penetrate Morpheus.