Block Oriented Programming: Automating Data-Only Attacks
Kyriakos K. Ispoglou, Bader AlBassam, Trent Jaeger, Mathias Payer
Abstract
With the widespread deployment of Control-Flow Integrity (CFI), control-flow hijacking attacks, and consequently code reuse attacks, are significantly more difficult. CFI limits control flow to well-known locations, severely restricting arbitrary code execution. Assessing the remaining attack surface of an application under advanced control-flow hijack defenses such as CFI and shadow stacks remains an open problem. We introduce BOPC, a mechanism to automatically assess whether an attacker can execute arbitrary code on a binary hardened with CFI/shadow stack defenses. BOPC computes exploits for a target program from payload specifications written in a Turing-complete, high-level language called SPL that abstracts away architecture and program-specific details. SPL payloads are compiled into a program trace that executes the desired behavior on top of the target binary. The input for BOPC is an SPL payload, a starting point (e.g., from a fuzzer crash) and an arbitrary memory write primitive that allows application state corruption. To map SPL payloads to a program trace, BOPC introduces Block Oriented Programming (BOP), a new code reuse technique that utilizes entire basic blocks as gadgets along valid execution paths in the program, i.e., without violating CFI or shadow stack policies. We find that the problem of mapping payloads to program traces is NP-hard, so BOPC first reduces the search space by pruning infeasible paths and then uses heuristics to guide the search to probable paths. BOPC encodes the BOP payload as a set of memory writes. We execute 13 SPL payloads applied to 10 popular applications. BOPC successfully finds payloads and complex execution traces -- which would likely not have been found through manual analysis -- while following the target's Control-Flow Graph under an ideal CFI policy in 81% of the cases.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 81f6a196-c851-4171-beef-58e0fa31af6fCited by top-tier papers56
- SoK: Shining Light on Shadow StacksNathan Burow, Xinping Zhang, Mathias PayerS&P 2019 · 170 citations
- Where Does It Go?: Refining Indirect-Call Targets with Multi-Layer Type AnalysisKangjie Lu, Hong HuCCS 2019 · 142 citations
- xMP: Selective Memory Protection for Kernel and User SpaceSergej Proskurin, Marius Momeu, Seyedhamed Ghavamnia, Vasileios P. Kemerlis et al.S&P 2020 · 89 citations
- SLAKE: Facilitating Slab Manipulation for Exploiting Vulnerabilities in the Linux KernelYueqi Chen, Xinyu XingCCS 2019 · 76 citations
- KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel VulnerabilitiesWei Wu, Yueqi Chen, Xinyu Xing, Wei ZouUSENIX Security 2019 · 75 citations
Builds on4
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- Efficient Protection of Path-Sensitive Control SecurityRen Ding, Chenxiong Qian, Chengyu Song, William Harris et al.USENIX Security 2017 · 123 citations
- The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years LaterVictor van der Veen, Dennis Andriesse, Manolis Stamatogiannakis, Xi Chen et al.CCS 2017 · 74 citations
Related papers
- A Generic Technique for Automatically Finding Defense-Aware Code Reuse AttacksEdward J. Schwartz, Cory F. Cohen, Jeffrey Gennari, Stephanie SchwartzCCS 2020 · 8 citations
- Crashing Through Defenses: Exploiting Segfaults and Chaining Around Intel CETMarcos Bajo, Ritvik Goyal, Apostolos Chatzianagnostou, Christian RossowS&P 2026
- Await() a Second: Evading Control Flow Integrity by Hijacking C++ CoroutinesMarcos Bajo, Christian RossowUSENIX Security 2025
- Burn after reading: a shadow stack with microsecond-level runtime rerandomization for protecting return addressesChangwei Zou, Jingling XueICSE 2020 · 6 citations
- SpecCFI: Mitigating Spectre Attacks using CFI Informed SpeculationEsmaeil Mohammadian Koruyeh, Shirin Haji Amin Shirazi, Khaled N. Khasawneh, Chengyu Song et al.S&P 2020 · 74 citations
