CFInsight: A Comprehensive Metric for CFI Policies
Tommaso Frassetto, Patrick Jauernig, David Koisser, Ahmad-Reza Sadeghi
Abstract
—Software vulnerabilities are one of the major threats to computer security and have caused substantial damage over the past decades. Consequently, numerous techniques have been proposed to mitigate the risk of exploitation of vulnerable programs. One of the most relevant defense mechanisms is Control-Flow Integrity (CFI): multiple variants have been introduced and extensively discussed in academia as well as deployed in the industry. However, it is hard to compare the security guarantees of these implementations as existing metrics (such as AIR) do not consider the different usefulness to the attacker of different basic blocks, which are the fundamental components that constitute the code of any application. This paper introduces B LOCK I NSULATION and CFGI NSU - LATION , novel metrics designed to overcome this limitation by modeling the usefulness of basic blocks for an attacker trying to traverse the program’s control-flow graph. Moreover, we propose a new CFI policy generator, named NumCFI, which is orthogonal to existing policy generators and prevents the attacker from taking shortcuts from vulnerable code to a system call instruction. We evaluate NumCFI, as well as a number of other CFI policy generators, using B LOCK I NSULATION , CFGI NSULATION , and existing metrics. Lastly, we describe L + T CFI, our implementation that combines NumCFI and an existing label-based policy, with a performance overhead of just 1.27%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2db944b6-5dac-4986-8e2d-d3eb5fa99dcfCited by top-tier papers4
- SHERLOC: Secure and Holistic Control-Flow Violation Detection on Embedded SystemsXi Tan, Ziming ZhaoCCS 2023 · 13 citations
- One for All and All for One: GNN-based Control-Flow Attestation for Embedded DevicesMarco Chilese, Richard Mitev, Meni Orenbach, Robert Thorburn et al.S&P 2024 · 11 citations
- Manipulative Interference AttacksSamuel Mergendahl, Stephen Fickas, Boyana Norris, Richard SkowyraCCS 2024 · 1 citation
- SoK: Integrity, Attestation, and Auditing of Program ExecutionMahmoud Ammar, Adam Caulfield, Ivan De Oliveira NunesS&P 2025
Builds on10
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary LevelVictor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski et al.S&P 2016 · 227 citations
- SoK: Shining Light on Shadow StacksNathan Burow, Xinping Zhang, Mathias PayerS&P 2019 · 170 citations
- HDFI: Hardware-Assisted Data-Flow IsolationChengyu Song, Hyungon Moon, Monjur Alam, Insu Yun et al.S&P 2016 · 146 citations
Related papers
- Finding Cracks in Shields: On the Security of Control Flow Integrity MechanismsYuan Li, Mingzhe Wang, Chao Zhang, Xingman Chen et al.CCS 2020 · 32 citations
- Block Oriented Programming: Automating Data-Only AttacksKyriakos K. Ispoglou, Bader AlBassam, Trent Jaeger, Mathias PayerCCS 2018 · 143 citations
- CONFIRM: Evaluating Compatibility and Relevance of Control-flow Integrity Protections for Modern SoftwareXiaoyang Xu, Masoud Ghaffarinia, Wenhao Wang, Kevin W. Hamlen et al.USENIX Security 2019 · 49 citations
- Origin-sensitive Control Flow IntegrityMustakimur Khandaker, Wenqing Liu, Abu Naser, Zhi Wang et al.USENIX Security 2019 · 71 citations
- Boosting Practical Control-Flow Integrity with Complete Field Sensitivity and Origin AwarenessHao Xiang, Zehui Cheng, Jinku Li, Jianfeng Ma et al.CCS 2024 · 2 citations
