A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level
Victor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski, Xi Chen, Sanjay Rawat, Herbert Bos, Thorsten Holz, Elias Athanasopoulos, Cristiano Giuffrida
摘要
Current binary-level Control-Flow Integrity (CFI) techniques are weak in determining the set of valid targets for indirect control flow transfers on the forward edge. In particular, the lack of source code forces existing techniques to resort to a conservative address-taken policy that overapproximates this set. In contrast, source-level solutions can accurately infer the targets of indirect callsites and thus detect malicious control-flow transfers more precisely. Given that source code is not always available, however, offering similar quality of protection at the binary level is important, but, unquestionably, more challenging than ever: recent work demonstrates powerful attacks, such as Counterfeit Objectoriented Programming (COOP), which made the community believe that protecting software against control-flow diversion attacks at the binary level is impossible. In this paper, we propose binary-level analysis techniques to significantly reduce the number of possible targets for indirect callsites. More specifically, we reconstruct a conservative approximation of target function prototypes by means of use-def analysis at possible callees. We then couple this with liveness analysis at each indirect callsite to derive a many-to-many relationship between callsites and target callees with a much higher precision compared to prior binary-level solutions. Experimental results on popular server programs and on SPEC CPU2006 show that TypeArmor, a prototype implementation of our approach, is efficient-with a runtime overhead of less than 3%. Furthermore, we evaluate to what extent TypeArmor can mitigate COOP and other advanced attacks and show that our approach can significantly reduce the number of targets on the forward edge. Moreover, we show that TypeArmor breaks published COOP exploits, providing concrete evidence that strict binary-level CFI can still mitigate advanced attacks, despite the absence of source information or C++ semantics.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper46
- Neural Nets Can Learn Function Type Signatures From BinariesZheng Leong Chua, Shiqi Shen, Prateek Saxena, Zhenkai LiangUSENIX Security 2017 · 被引用 175 次
- An In-Depth Analysis of Disassembly on Full-Scale x86/x64 BinariesDennis Andriesse, Xi Chen, Victor van der Veen, Asia Slowinska 等USENIX Security 2016 · 被引用 162 次
- Where Does It Go?: Refining Indirect-Call Targets with Multi-Layer Type AnalysisKangjie Lu, Hong HuCCS 2019 · 被引用 142 次
- Enforcing Unique Code Target Property for Control-Flow IntegrityHong Hu, Chenxiong Qian, Carter Yagemann, Simon Pak Ho Chung 等CCS 2018 · 被引用 142 次
- Superset Disassembly: Statically Rewriting x86 Binaries Without HeuristicsErick Bauman, Zhiqiang Lin, Kevin W. HamlenNDSS 2018 · 被引用 112 次
相关 Paper
- TypeSqueezer: When Static Recovery of Function Signatures for Binary Executables Meets Dynamic AnalysisZiyi Lin, Jinku Li, Bowen Li, Haoyu Ma 等CCS 2023 · 被引用 7 次
- Improving Indirect-Call Analysis in LLVM with Type and Data-Flow Co-AnalysisDinghao Liu, Shouling Ji, Kangjie Lu, Qinming HeUSENIX Security 2024 · 被引用 13 次
- VScape: Assessing and Escaping Virtual Call ProtectionsKaixiang Chen, Chao Zhang, Tingting Yin, Xingman Chen 等USENIX Security 2021 · 被引用 5 次
- Refining Indirect Call Targets at the Binary LevelSun Hyoung Kim, Cong Sun, Dongrui Zeng, Gang TanNDSS 2021
- Boosting Practical Control-Flow Integrity with Complete Field Sensitivity and Origin AwarenessHao Xiang, Zehui Cheng, Jinku Li, Jianfeng Ma 等CCS 2024 · 被引用 2 次
