USENIX Security Symposium · 2013 · 266 citations · 32 references
EngineeringInformation SecuritySoftware EngineeringPractical Runtime RopSide-channel AttackSoftware AnalysisHardware SecurityTransparent RopSystems EngineeringRop ExploitsTrusted Execution EnvironmentRuntime VerificationOperating System SecurityComputer EngineeringSecure By DesignComputer ScienceLanguage-based SecurityData SecuritySoftware SecurityProgram AnalysisReturn-oriented ProgrammingSoftware TestingSystem Software
Return-oriented programming (ROP) has become the primary exploitation technique for system compromise in the presence of non-executable page protections. ROP exploits are facilitated mainly by the lack of complete address space randomization coverage or the presence of memory disclosure vulnerabilities, necessitating additional ROP-specific mitigations. In this paper we present a practical runtime ROP exploit prevention technique for the protection of third-party applications. Our approach is based on the detection of abnormal control transfers that take place during ROP code execution. This is achieved using hardware features of commodity processors, which incur negligible runtime overhead and allow for completely transparent operation without requiring any modifications to the protected applications. Our implementation for Windows 7, named kBouncer, can be selectively enabled for installed programs in the same fashion as user-friendly mitigation toolkits like Microsoft's EMET. The results of our evaluation demonstrate that kBouncer has low runtime overhead of up to 4%, when stressed with specially crafted workloads that continuously trigger its core detection component, while it has negligible overhead for actual user applications. In our experiments with in-the-wild ROP exploits, kBouncer successfully protected all tested applications, including Internet Explorer, Adobe Flash Player, and Adobe Reader.
32
Chi-Keung Luk, Robert Cohn, Robert Muth et al. · ACM SIGPLAN Notices · 2005 · 3.2K citations
Engineering, Computer Architecture, Software Engineering +16
The geometry of innocent flesh on the bone
Hovav Shacham · 2007 · 1.3K citations
Martı́n Abadi, Mihai Budiu, Úlfar Erlingsson et al. · 2005 · 1K citations
Current Software Attacks, Software Security, Engineering +15
On the effectiveness of address-space randomization
Hovav Shacham, Matthew J. Page, Ben Pfaff et al. · 2004 · 854 citations
Engineering, Information Security, Computer Architecture +22
Return-oriented programming without returns
Stephen Checkoway, Lucas Davi, Alexandra Dmitrienko et al. · 2010 · 534 citations
Return-oriented Programming Attacks, Large Libraries, Engineering +20