2015 · 293 citations · 33 references
Flow ControlEngineeringInformation SecurityMechanical EngineeringComputer ArchitectureSide-channel AttackSoftware AnalysisFormal VerificationHardware SecurityUnsteady FlowMechanicsSystems EngineeringSecure ComputingStatic CfiComputer EngineeringFlow Control (Data)Computer ScienceStatic Program AnalysisLanguage-based SecurityData SecuritySoftware SecurityProgram AnalysisControl-flow IntegrityMechanical SystemsProcess ControlControl-flow BendingAerodynamicsControl Structure
Control-Flow Integrity (CFI) is a defense which prevents control-flow hijacking attacks. While recent research has shown that coarse-grained CFI does not stop attacks, fine-grained CFI is believed to be secure. We argue that assessing the effectiveness of practical CFI implementations is non-trivial and that common evaluation metrics fail to do so. We then evaluate fullyprecise static CFI -- the most restrictive CFI policy that does not break functionality -- and reveal limitations in its security. Using a generalization of non-control-data attacks which we call Control-Flow Bending (CFB), we show how an attacker can leverage a memory corruption vulnerability to achieve Turing-complete computation on memory using just calls to the standard library. We use this attack technique to evaluate fully-precise static CFI on six real binaries and show that in five out of six cases, powerful attacks are still possible. Our results suggest that CFI may not be a reliable defense against memory corruption vulnerabilities. We further evaluate shadow stacks in combination with CFI and find that their presence for security is necessary: deploying shadow stacks removes arbitrary code execution capabilities of attackers in three of six cases.
33
The geometry of innocent flesh on the bone
Hovav Shacham · 2007 · 1.3K citations
StackGuard: automatic adaptive detection and prevention of buffer-overflow attacks
Crispin Cowan, Calton Pu, Dave Maier et al. · PDXScholar (Portland State University) · 1998 · 1.3K citations · Full text
Martı́n Abadi, Mihai Budiu, Úlfar Erlingsson et al. · 2005 · 1K citations
Current Software Attacks, Software Security, Engineering +15
László Szekeres, Mathias Payer, Tao Wei et al. · 2013 · 640 citations · Full text
Engineering, Information Security, Memory Model (Programming) +21
Trevor Jim, J. Greg Morrisett, Dan Grossman et al. · 2002 · 617 citations