Origin-sensitive Control Flow Integrity
Mustakimur Khandaker, Wenqing Liu, Abu Naser, Zhi Wang, Jie Yang
摘要
CFI is an effective, generic defense against control-flow hijacking attacks, especially for C/C++ programs. However, most previous CFI systems have poor security as demonstrated by their large equivalence class (EC) sizes. An EC is a set of targets that are indistinguishable from each other in the CFI policy; i.e., an attacker can "bend" the control flow within an EC without being detected. As such, the large ECs denote the weakest link in a CFI system and should be broken down in order to improve security. An approach to improve the security of CFI is to use contextual information, such as the last branches taken, to refine the CFI policy, the so-called context-sensitive CFI. However, contexts based on the recent execution history are often inadequate in breaking down large ECs due to the limited number of incoming execution paths to an indirect control transfer instruction (ICT).1 In this paper, we propose a new context for CFI, origin sensitivity, that can effectively break down large ECs and reduce the average and largest EC size. Origin-sensitive CFI (OS-CFI) takes the origin of the code pointer called by an ICT as the context and constrains the targets of the ICT with this context. It supports both C-style indirect calls and C++ virtual calls. Additionally, we leverage common hardware features in the commodity Intel processors (MPX and TSX) to improve both security and performance of OS-CFI. Our evaluation shows that OS-CFI can substantially reduce the largest and average EC sizes (by 98% in some cases) and has strong performance -7.6% overhead on average for all C/C++ benchmarks of SPEC CPU2006 and NGINX.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper22
- Finding Cracks in Shields: On the Security of Control Flow Integrity MechanismsYuan Li, Mingzhe Wang, Chao Zhang, Xingman Chen 等CCS 2020 · 被引用 32 次
- Unleashing the Power of Type-Based Call Graph Construction by Using Regional Pointer InformationYuandao Cai, Yibo Jin, Charles ZhangUSENIX Security 2024 · 被引用 16 次
- Protect the System Call, Protect (Most of) the World with BASTIONChristopher Jelesnianski, Mohannad Ismail, Yeongjin Jang, Dan Williams 等ASPLOS 2023 · 被引用 15 次
- SHERLOC: Secure and Holistic Control-Flow Violation Detection on Embedded SystemsXi Tan, Ziming ZhaoCCS 2023 · 被引用 13 次
- On Bridging the Gap between Control Flow Integrity and Attestation SchemesMahmoud Ammar, Ahmed Abdelraoof, Silviu VlasceanuUSENIX Security 2024 · 被引用 9 次
它引用的顶会 Paper5
- SoK: Shining Light on Shadow StacksNathan Burow, Xinping Zhang, Mathias PayerS&P 2019 · 被引用 170 次
- Enforcing Unique Code Target Property for Control-Flow IntegrityHong Hu, Chenxiong Qian, Carter Yagemann, Simon Pak Ho Chung 等CCS 2018 · 被引用 142 次
- Efficient Protection of Path-Sensitive Control SecurityRen Ding, Chenxiong Qian, Chengyu Song, William Harris 等USENIX Security 2017 · 被引用 123 次
- VTrust: Regaining Trust on Virtual CallsChao Zhang, Dawn Song, Scott A. Carr, Mathias Payer 等NDSS 2016 · 被引用 91 次
- CFIXX: Object Type Integrity for C++Nathan Burow, Derrick Paul McKee, Scott A. Carr, Mathias PayerNDSS 2018 · 被引用 56 次
相关 Paper
- Boosting Practical Control-Flow Integrity with Complete Field Sensitivity and Origin AwarenessHao Xiang, Zehui Cheng, Jinku Li, Jianfeng Ma 等CCS 2024 · 被引用 2 次
- SpecCFI: Mitigating Spectre Attacks using CFI Informed SpeculationEsmaeil Mohammadian Koruyeh, Shirin Haji Amin Shirazi, Khaled N. Khasawneh, Chengyu Song 等S&P 2020 · 被引用 74 次
- PIBE: practical kernel control-flow hardening with profile-guided indirect branch eliminationVictor Duta, Cristiano Giuffrida, Herbert Bos, Erik van der KouweASPLOS 2021 · 被引用 12 次
- A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary LevelVictor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski 等S&P 2016 · 被引用 227 次
- Pythia: Compiler-Guided Defense Against Non-Control Data AttacksSharjeel Khan, Bodhisatwa Chatterjee, Santosh PandeASPLOS 2024 · 被引用 2 次
