PLaTypus: Restricting Cross-Module Transitions to Mitigate Code-Reuse Attacks
Apostolos Chatzianagnostou, Marcos Bajo, Christian Rossow
Abstract
Numerous techniques have been proposed to thwart code reuse attacks, yet practical adoption remains limited due to compatibility and deployment challenges. In the current and foreseeable Intel architecture landscape, the main line of defense against such attacks is Intel CET-a hardwareenforced control-flow integrity mechanism integrated into recent Intel x86-64 CPUs. However, despite its hardware-backed protections and widespread adoption, CET still provides only partial security: it continues to allow hijacked function pointers to invoke arbitrary functions across module boundaries, a capability that remains fundamental to many modern exploits. This paper proposes PLATYPUS, a novel defense on top of Intel CET to address this limitation. PLATYPUS enforces execution jails using lightweight address masking to ensure indirect control transfers remain within module boundaries. Cross-DSO function calls are only permitted via necessary PLT stubs specific to each DSO. The evaluation on our LLVM-based prototype, spanning 19 applications and 16 shared libraries (including glibc), demonstrates that PLATYPUS reduces indirectly accessible cross-DSO functions by over 98 %. Performance testing with complex applications like Nginx and Redis shows that PLATYPUS incurs no more than 0.5 % overhead.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Crashing Through Defenses: Exploiting Segfaults and Chaining Around Intel CETMarcos Bajo, Ritvik Goyal, Apostolos Chatzianagnostou, Christian RossowS&P 2026
- CETIS: Retrofitting Intel CET for Generic and Efficient Intra-process Memory IsolationMengyao Xie, Chenggang Wu, Yinqian Zhang, Jiali Xu et al.CCS 2022 · 14 citations
- Hurdle: Securing Jump Instructions Against Code Reuse AttacksChristian DeLozier, Kavya Lakshminarayanan, Gilles Pokam, Joseph DeviettiASPLOS 2020 · 6 citations
- IMIX: In-Process Memory Isolation EXtensionTommaso Frassetto, Patrick Jauernig, Christopher Liebchen, Ahmad-Reza SadeghiUSENIX Security 2018 · 77 citations
- SpecCFI: Mitigating Spectre Attacks using CFI Informed SpeculationEsmaeil Mohammadian Koruyeh, Shirin Haji Amin Shirazi, Khaled N. Khasawneh, Chengyu Song et al.S&P 2020 · 74 citations
