Address Oblivious Code Reuse: On the Effectiveness of Leakage Resilient Diversity
Robert Rudd, Richard Skowyra, David Bigelow, Veer Dedhia, Thomas Hobson, Stephen Crane, Christopher Liebchen, Per Larsen, Lucas Davi, Michael Franz, Ahmad-Reza Sadeghi, Hamed Okhravi
摘要
Memory corruption vulnerabilities not only allow modification of control data and injection of malicious payloads; they also allow adversaries to reconnoiter a diversified program, customize a payload, and ultimately bypass code randomization defenses. In response, researchers have proposed and built various leakage-resilient defenses against code reuse. Leakage-resilient defenses use memory protection techniques to prevent adversaries from directly reading code as well as pointer indirection or encryption techniques to decouple code pointers from the randomized code layout, avoiding indirect leakage. In this paper, we show that although current code pointer protections do prevent leakage per se, they are fundamentally unable to stop code reuse. Specifically, we demonstrate a new class of attacks we call address-oblivious code reuse that bypasses state-of-the-art leakage-resilience techniques by profiling and reusing protected code pointers, without leaking the code layout. We show that an attacker can accurately identify protected code pointers of interest and mount code-reuse attacks at the abstraction level of pointers without requiring any knowledge of code addresses. We analyze the prevalence of opportunities for such attacks in popular code bases and build three real-world exploits against Nginx and Apache to demonstrate their practicality. We analyze recently proposed leakage resilient defenses and show that they are vulnerable to address oblivious code reuse. Our findings indicate that because of the prevalence of code pointers in realistic programs and the fundamental need to expose them to "read" operations (even indirectly), diversity defenses face a fundamental design challenge in mitigating such attacks. DISTRIBUTION STATEMENT A. Approved for public release: distribution unlimited.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- Compiler-Assisted Code RandomizationHyungjoon Koo, Yaohui Chen, Long Lu, Vasileios P. Kemerlis 等S&P 2018 · 被引用 80 次
- The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years LaterVictor van der Veen, Dennis Andriesse, Manolis Stamatogiannakis, Xi Chen 等CCS 2017 · 被引用 74 次
- NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64Yaohui Chen, Dongli Zhang, Ruowen Wang, Rui Qiao 等S&P 2017 · 被引用 46 次
- Speculative Probing: Hacking Blind in the Spectre EraEnes Göktas, Kaveh Razavi, Georgios Portokalidis, Herbert Bos 等CCS 2020 · 被引用 36 次
- Methodologies for Quantifying (Re-)randomization Security and Timing under JIT-ROPSalman Ahmed, Ya Xiao, Kevin Z. Snow, Gang Tan 等CCS 2020 · 被引用 21 次
它引用的顶会 Paper10
- Flip Feng Shui: Hammering a Needle in the Software StackKaveh Razavi, Ben Gras, Erik Bosman, Bart Preneel 等USENIX Security 2016 · 被引用 306 次
- Dedup Est Machina: Memory Deduplication as an Advanced Exploitation VectorErik Bosman, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaS&P 2016 · 被引用 252 次
- A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary LevelVictor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski 等S&P 2016 · 被引用 227 次
- How to Make ASLR Win the Clone Wars: Runtime Re-RandomizationKangjie Lu, Wenke Lee, Stefan Nürnberger, Michael BackesNDSS 2016 · 被引用 96 次
- Poking Holes in Information HidingAngelos Oikonomopoulos, Elias Athanasopoulos, Herbert Bos, Cristiano GiuffridaUSENIX Security 2016 · 被引用 92 次
相关 Paper
- Leakage-Resilient Layout Randomization for Mobile DevicesKjell Braden, Lucas Davi, Christopher Liebchen, Ahmad-Reza Sadeghi 等NDSS 2016 · 被引用 90 次
- What Cannot Be Read, Cannot Be Leveraged? Revisiting Assumptions of JIT-ROP DefensesGiorgi Maisuradze, Michael Backes, Christian RossowUSENIX Security 2016 · 被引用 41 次
- SafeHidden: An Efficient and Secure Information Hiding Technique Using Re-randomizationZhe Wang, Chenggang Wu, Yinqian Zhang, Bowen Tang 等USENIX Security 2019 · 被引用 18 次
- Return to the Zombie Gadgets: Undermining Destructive Code Reads via Code Inference AttacksKevin Z. Snow, Roman Rogowski, Jan Werner, Hyungjoon Koo 等S&P 2016 · 被引用 54 次
- IMIX: In-Process Memory Isolation EXtensionTommaso Frassetto, Patrick Jauernig, Christopher Liebchen, Ahmad-Reza SadeghiUSENIX Security 2018 · 被引用 77 次
