2015 · 122 citations · 45 references
EngineeringSoftware AnalysisFormal VerificationCompilersRuntime VerificationOperating System SecurityComputer EngineeringChromium Web BrowserComputer ScienceStatic Program AnalysisLanguage-based SecurityControl FlowSoftware SecurityOperating SystemsProgram AnalysisSoftware TestingFormal MethodsStack ContentsSystem Software
Adversaries exploit memory corruption vulnerabilities to hijack a program's control flow and gain arbitrary code execution. One promising mitigation, control-flow integrity (CFI), has been the subject of extensive research in the past decade. One of the core findings is that adversaries can construct Turing-complete code-reuse attacks against coarse-grained CFI policies because they admit control flows that are not part of the original program. This insight led the research community to focus on fine-grained CFI implementations. In this paper we show how to exploit heap-based vulnerabilities to control the stack contents including security-critical values used to validate control-flow transfers. Our investigation shows that although program analysis and compiler-based mitigations reduce stack-based vulnerabilities, stack-based memory corruption remains an open problem. Using the Chromium web browser we demonstrate real-world attacks against various CFI implementations: 1)~against CFI implementations under Windows 32-bit by exploiting unprotected context switches, and 2)~against state-of-the-art fine-grained CFI implementations (IFCC and VTV) in the two premier open-source compilers under Unix-like operating systems. Both 32 and 64-bit x86 CFI checks are vulnerable to stack manipulation. Finally, we provide an exploit technique against the latest shadow stack implementation.
45
The geometry of innocent flesh on the bone
Hovav Shacham · 2007 · 1.3K citations
StackGuard: automatic adaptive detection and prevention of buffer-overflow attacks
Crispin Cowan, Calton Pu, Dave Maier et al. · PDXScholar (Portland State University) · 1998 · 1.3K citations · Full text
Efficient software-based fault isolation
Robert Wahbe, Steven Lucco, Thomas E. Anderson et al. · 1993 · 1.2K citations · Full text
Software Maintenance, Engineering, Computer Architecture +19
Martı́n Abadi, Mihai Budiu, Úlfar Erlingsson et al. · 2005 · 1K citations
Current Software Attacks, Software Security, Engineering +15
Smashing The Stack For Fun And Profit
A. One · Medical Entomology and Zoology · 1996 · 767 citations