SGXPecial: Specializing SGX Interfaces against Code Reuse Attacks

SGXPecial: Specializing SGX Interfaces against Code Reuse Attacks
复制标题

DOI:
10.1145/3447852.3458716
复制
发表时间:
2021-04
期刊:
Proceedings of the 14th European Workshop on Systems Security
影响因子:
--
通讯作者:
Shachee Mishra;M. Polychronakis
Shachee Mishra;M. Polychronakis
中科院分区:
其他
文献类型:
--
作者:
Shachee Mishra;M. Polychronakis

文献摘要

被引文献

相似文献

英特尔SGX是一种基于硬件的可信执行技术,可将应用程序划分为可信和不可信部分。被称为安全区的可信部分在加密的内存环境中执行,阻止主机应用程序和操作系统访问其内存。然而,安全区具有访问主机的存储器的能力。当考虑在飞地中运行的恶意代码时,所提供的强存储器隔离和加密属性可以帮助恶意软件的隐蔽性,因为恶意软件检测工具不能检查飞地。安全区和主机通过英特尔SGX SDK生成的双向接口进行通信。在这项工作中,我们提出了SGXPecial,一个尽最大努力的接口专业化工具,静态分析主机和飞地,以生成仅根据其需求量身定制的接口。SGXPecial作为SGX SDK的Edger8r工具的扩展实现,并在构建时执行API专门化。特别是,SGXPecial执行基于函数、参数和类型的专门化,以限制跨主机到安全区边界的有效控制流。我们通过在SGX SDK示例应用程序和四个开源SGX应用程序上进行测试来评估SGXPecial的安全影响。SGXPecial在所有测试的应用程序中有效地防止了五种概念验证代码重用攻击。
Intel SGX is a hardware-based trusted execution technology that partitions an application into trusted and untrusted parts. The trusted part, known as an enclave, executes within an encrypted memory environment, preventing the host application and the OS from being able to access its memory. The enclave, however, has the ability to access the host's memory. When considering malicious code running in an enclave, the strong memory isolation and encryption properties offered may aid the stealthiness of malware, since malware detection tools cannot inspect the enclave. The enclave and the host communicate over bi-directional interfaces that the Intel SGX SDK generates. In this work, we present SGXPecial, a best-effort interface specialization tool that statically analyzes both the host and the enclave to generate interfaces tailored only to their needs. SGXPecial is implemented as an extension to the Edger8r tool of the SGX SDK, and performs API specialization at build time. In particular, SGXPecial performs function, argument, and type-based specialization to restrict the valid control flows across the host-to-enclave boundary. We evaluate SGXPecial's security impact by testing it on SGX SDK sample applications and four open-source SGX applications. SGXPecial effectively prevents five proof-of-concept code reuse attacks in all tested applications.