Countering code-injection attacks with instruction-set randomization

Gaurav S. Kc, Angelos D. Keromytis, Vassilis Prevelakis

2003 · 53 citations · 0 references

Concepts

TL;DR

Code‑injection attacks rely on executing injected code, but without the randomization key the code becomes invalid and triggers a runtime exception. The paper proposes a general method to safeguard systems against all code‑injection attacks. The authors generate process‑specific randomized instruction sets per Kerckhoff's principle, modify the Linux kernel, GNU binutils, and Bochs‑x86 emulator, and adapt the Perl interpreter to enable randomized execution. Prototype tests confirm feasibility, showing a significant performance penalty on native hardware but minimal overhead in interpreted languages, and indicating the method can serve as a low‑overhead complement to other defenses.

Abstract

We describe a new, general approach for safeguarding systems against any type of code-injection attack. We apply Kerckhoff's principle, by creating process-specific randomized instruction sets (e.g., machine instructions) of the system executing potentially vulnerable software. An attacker who does not know the key to the randomization algorithm will inject code that is invalid for that randomized processor, causing a runtime exception. To determine the difficulty of integrating support for the proposed mechanism in the operating system, we modified the Linux kernel, the GNU binutils tools, and the bochs-x86 emulator. Although the performance penalty is significant, our prototype demonstrates the feasibility of the approach, and should be directly usable on a suitable-modified processor (e.g., the Transmeta Crusoe).Our approach is equally applicable against code-injecting attacks in scripting and interpreted languages, e.g., web-based SQL injection. We demonstrate this by modifying the Perl interpreter to permit randomized script execution. The performance penalty in this case is minimal. Where our proposed approach is feasible (i.e., in an emulated environment, in the presence of programmable or specialized hardware, or in interpreted languages), it can serve as a low-overhead protection mechanism, and can easily complement other mechanisms.