USENIX Security2016Top-tier venue
Poking Holes in Information Hiding
Angelos Oikonomopoulos, Elias Athanasopoulos, Herbert Bos, Cristiano Giuffrida
Abstract
ASLR is no longer a strong defense in itself, but it still serves as a foundation for sophisticated defenses that use randomization for pseudo-isolation. Crucially, these defenses hide sensitive information (such as shadow stacks and safe regions) at a random position in a very large address space. Previous attacks on randomization-based information hiding rely on complicated side channels and/or probing of the mapped memory regions. Assuming no weaknesses exist in the implementation of hidden regions, the attacks typically lead to many crashes or other visible side-effects. For this reason, many researchers still consider the pseudo-isolation offered by ASLR sufficiently strong in practice. We introduce powerful new primitives to show that this faith in ASLR-based information hiding is misplaced, and that attackers can break ASLR and find hidden regions on 32 bit and 64 bit Linux systems quickly with very few malicious inputs. Rather than building on memory accesses that probe the allocated memory areas, we determine the sizes of the unallocated holes in the address space by repeatedly allocating large chunks of memory. Given the sizes, an attacker can infer the location of the hidden region with few or no side-effects. We show that allocation oracles are pervasive and evaluate our primitives on real-world server applications.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers20
- SoK: Shining Light on Shadow StacksNathan Burow, Xinping Zhang, Mathias PayerS&P 2019 · 170 citations
- Enforcing Unique Code Target Property for Control-Flow IntegrityHong Hu, Chenxiong Qian, Carter Yagemann, Simon Pak Ho Chung et al.CCS 2018 · 142 citations
- TypeSan: Practical Type Confusion DetectionIstván Haller, Yuseok Jeon, Hui Peng, Mathias Payer et al.CCS 2016 · 97 citations
- Undermining Information Hiding (and What to Do about It)Enes Göktas, Robert Gawlik, Benjamin Kollenda, Elias Athanasopoulos et al.USENIX Security 2016 · 82 citations
- Address Oblivious Code Reuse: On the Effectiveness of Leakage Resilient DiversityRobert Rudd, Richard Skowyra, David Bigelow, Veer Dedhia et al.NDSS 2017 · 78 citations
Builds on4
- Dedup Est Machina: Memory Deduplication as an Advanced Exploitation VectorErik Bosman, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaS&P 2016 · 252 citations
- Leakage-Resilient Layout Randomization for Mobile DevicesKjell Braden, Lucas Davi, Christopher Liebchen, Ahmad-Reza Sadeghi et al.NDSS 2016 · 90 citations
- Undermining Information Hiding (and What to Do about It)Enes Göktas, Robert Gawlik, Benjamin Kollenda, Elias Athanasopoulos et al.USENIX Security 2016 · 82 citations
- Enabling Client-Side Crash-Resistance to Overcome Diversification and Information HidingRobert Gawlik, Benjamin Kollenda, Philipp Koppe, Behrad Garmany et al.NDSS 2016 · 77 citations
Related papers
- When Good Kernel Defenses Go Bad: Reliable and Stable Kernel Exploits via Defense-Amplified TLB Side-Channel LeaksLukas Maar, Lukas Giner, Daniel Gruss, Stefan MangardUSENIX Security 2025
- SafeHidden: An Efficient and Secure Information Hiding Technique Using Re-randomizationZhe Wang, Chenggang Wu, Yinqian Zhang, Bowen Tang et al.USENIX Security 2019 · 18 citations
- Oreo: Protecting ASLR Against Microarchitectural AttacksShixin Song, Joseph Zhang, Mengjia YanNDSS 2025
- AVX Timing Side-Channel Attacks against Address Space Layout RandomizationHyunwoo Choi, Suryeon Kim, Seungwon ShinDAC 2023 · 5 citations
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp et al.CCS 2016 · 278 citations
