2015 · 165 citations · 14 references
EngineeringIntel® Siskiyou PeakInformation SecurityComputer ArchitectureCode-reuse AttacksEmbedded SystemsSoftware AnalysisHardware SecurityTrusted Execution EnvironmentHardware Security SolutionOperating System SecurityComputer EngineeringComputer ScienceLanguage-based SecurityData SecuritySoftware SecurityProgram AnalysisReturn-oriented ProgrammingSystem Software
Code-reuse attacks like return-oriented programming (ROP) pose a severe threat to modern software on diverse processor architectures. Designing practical and secure defenses against code-reuse attacks is highly challenging and currently subject to intense research. However, no secure and practical system-level solutions exist so far, since a large number of proposed defenses have been successfully bypassed. To tackle this attack, we present HAFIX (Hardware-Assisted Flow Integrity eXtension), a defense against code-reuse attacks exploiting backward edges (returns). HAFIX provides fine-grained and practical protection, and serves as an enabling technology for future control-flow integrity instantiations. This paper presents the implementation and evaluation of HAFIX for the Intel® Siskiyou Peak and SPARC embedded system architectures, and demonstrates its security and efficiency in code-reuse protection while incurring only 2% performance overhead.
14
The geometry of innocent flesh on the bone
Hovav Shacham · 2007 · 1.3K citations
Return-oriented programming without returns
Stephen Checkoway, Lucas Davi, Alexandra Dmitrienko et al. · 2010 · 534 citations
Return-oriented Programming Attacks, Large Libraries, Engineering +20
Control flow integrity for COTS binaries
Mingwei Zhang, R. Sekar · 2013 · 378 citations
Out of Control: Overcoming Control-Flow Integrity
Enes Göktaş, Herbert Bos, Georgios Portokalidis · 2014 · 354 citations · Full text