arrow
返回

ROPSentry: Runtime defense against ROP attacks using hardware performance counters

delete2018-03-01
delete16
PRE
AI
D
Das, Sanjeeu *
B
Bihuan Chen *
M
Mahintham Chandramohan
刘洋 (Yang Liu)
W
Wei Zhang
DOI:10.1016/j.cose.2017.11.011delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Return-Oriented Programming (ROP) is one of the most common techniques to exploit software vulnerabilities. However, existing defense techniques can be defeated by attackers, or suffer from high performance overhead. In this paper, we propose a defense framework, named ROPSentry, to detect ROP attacks at runtime. It is built on the observation that ROP exploits usually trigger different hardware events than normal programs generated by compilers. Hence, we leverage hardware performance counters to track such hardware events and analyze behavioral patterns of ROP attacks. ROPSentry has two approaches. The ROP-only defense approach detects ROP attacks via capturing the patterns of ROP exploits, where we propose to sample the hardware performance counters at mispredicted return events instead of at every microinstruction for a low performance overhead. To further reduce performance overhead, we propose a self-adaptive defense approach to dynamically switch between low and high sampling rates. It detects the patterns of spraying attacks (i.e., one common ROP payload delivery technique) at a low sampling rate, and then switches to a high sampling rate for detecting the patterns of ROP exploits. Our evaluation on 11 real-world ROP exploits, 50 synthetically generated ROP exploits and 1000 benign websites has shown that, the ROP-only and self-adaptive approaches are effective in detecting ROP attacks with low performance overhead (11% and 1% respectively) as well as low false positive; and they significantly outperform the state-of-the-art techniques in terms of performance overhead without losing the detection accuracy. (C) 2017 Elsevier Ltd. All rights reserved.
Keyword:
ROP attacks
Hardware performance counter
Code-reuse attacks
Memory corruption attacks
Runtime memory attacks
Exploit defense
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

F
fudan university
学者数:
11.8W
论文数: 7.7W
被引数: 121
U
university of north carolina
学者数:
7.4W
论文数: 6.5W
被引数: 93
U
University of North Carolina School of Medicine
学者数:
1.6W
论文数: 1.1W
被引数: 20
U
University of North Carolina Chapel Hill
学者数:
3.9W
论文数: 3.1W
被引数: 46
学者 查看更多机构
引用论文

引用论文

Spectroscopic Imaging of Quasiparticle Bound States Induced by Strong Nonmagnetic Scatterings in One-Unit-Cell FeSe/SrTiO3
err2019-07-15
err0
PREAI
errChaofei Liu; Ziqiao Wang; Yi Gao; Xiaoqiang Liu; Yi Liu; Qiang-Hua Wang; Jian Wang
err分享
err收藏