NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64
Yaohui Chen, Dongli Zhang, Ruowen Wang, Rui Qiao, Ahmed M. Azab, Long Lu, Hayawardh Vijayakumar, Wenbo Shen
Abstract
Code reuse attacks exploiting memory disclosure vulnerabilities can bypass all deployed mitigations. One promising defense against this class of attacks is to enable executeonly memory (XOM) protection on top of fine-grained address space layout randomization (ASLR). However, recent works implementing XOM, despite their efficacy, only protect programs that have been (re)built with new compiler support, leaving commercial-off-the-shelf (COTS) binaries and source-unavailable programs unprotected. We present the design and implementation of NORAX, a practical system that retrofits XOM into stripped COTS binaries on AArch64 platforms. Unlike previous techniques, NORAX requires neither source code nor debugging symbols. NORAX statically transforms existing binaries so that during runtime their code sections can be loaded into XOM memory pages with embedded data relocated and data references properly updated. NORAX allows transformed binaries to leverage the new hardware-based XOM support-a feature widely available on AArch64 platforms (e.g., recent mobile devices) yet virtually unused due to the incompatibility of existing binaries. Furthermore, NORAX is designed to co-exist with other COTS binary hardening techniques, such as in-place randomization (IPR). We apply NORAX to the commonly used Android system binaries running on SAMSUNG Galaxy S6 and LG Nexus 5X devices. The results show that NORAX on average slows down the execution of transformed binaries by 1.18% and increases their memory footprint by 2.21%, suggesting NORAX is practical for real-world adoption.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 359c82d0-2f8a-4e1a-a11c-22e3daa4e704Cited by top-tier papers12
- SoK: All You Ever Wanted to Know About x86/x64 Binary Disassembly But Were Afraid to AskChengbin Pang, Ruotong Yu, Yaohui Chen, Eric Koskinen et al.S&P 2021 · 102 citations
- xMP: Selective Memory Protection for Kernel and User SpaceSergej Proskurin, Marius Momeu, Seyedhamed Ghavamnia, Vasileios P. Kemerlis et al.S&P 2020 · 89 citations
- Compiler-Assisted Code RandomizationHyungjoon Koo, Yaohui Chen, Long Lu, Vasileios P. Kemerlis et al.S&P 2018 · 80 citations
- uXOM: Efficient eXecute-Only Memory on ARM Cortex-MDonghyun Kwon, Jangseop Shin, Giyeol Kim, Byoungyoung Lee et al.USENIX Security 2019 · 40 citations
- Speculative Probing: Hacking Blind in the Spectre EraEnes Göktas, Kaveh Razavi, Georgios Portokalidis, Herbert Bos et al.CCS 2020 · 36 citations
Builds on4
- An In-Depth Analysis of Disassembly on Full-Scale x86/x64 BinariesDennis Andriesse, Xi Chen, Victor van der Veen, Asia Slowinska et al.USENIX Security 2016 · 162 citations
- Leakage-Resilient Layout Randomization for Mobile DevicesKjell Braden, Lucas Davi, Christopher Liebchen, Ahmad-Reza Sadeghi et al.NDSS 2016 · 90 citations
- Address Oblivious Code Reuse: On the Effectiveness of Leakage Resilient DiversityRobert Rudd, Richard Skowyra, David Bigelow, Veer Dedhia et al.NDSS 2017 · 78 citations
- Return to the Zombie Gadgets: Undermining Destructive Code Reads via Code Inference AttacksKevin Z. Snow, Roman Rogowski, Jan Werner, Hyungjoon Koo et al.S&P 2016 · 54 citations
Related papers
- Retrofitting XoM for Stripped Binaries without Embedded Data RelocationChenke Luo, Jiang Ming, Mengfei Xie, Guojun Peng et al.NDSS 2025
- MemoryTrap: Booby Trapping Memory to Counter Memory Disclosure Attacks with Hardware SupportChenke Luo, Jiang Ming, Dongpeng Xu, Guojun Peng et al.USENIX ATC 2025
- What Cannot Be Read, Cannot Be Leveraged? Revisiting Assumptions of JIT-ROP DefensesGiorgi Maisuradze, Michael Backes, Christian RossowUSENIX Security 2016 · 41 citations
- Breaking Kernel Address Space Layout Randomization with Intel TSXYeongjin Jang, Sangho Lee, Taesoo KimCCS 2016 · 174 citations
- Drammer: Deterministic Rowhammer Attacks on Mobile PlatformsVictor van der Veen, Yanick Fratantonio, Martina Lindorfer, Daniel Gruss et al.CCS 2016 · 381 citations
