Practical Data-Only Attack Generation
Brian Johannesmeyer, Asia Slowinska, Herbert Bos, Cristiano Giuffrida
摘要
As control-flow hijacking is getting harder due to increasingly sophisticated CFI solutions, recent work has instead focused on automatically building data-only attacks, typically using symbolic execution, simplifying assumptions that do not always match the attacker's goals, manual gadget chaining, or all of the above. As a result, the practical adoption of such methods is minimal. In this work, we abstract away unnecessary complexities and instead use a lightweight approach that targets the vulnerabilities that are both the most tractable for analysis, and the most promising for an attacker. In particular, we present EINSTEIN, a data-only attack exploitation pipeline that uses dynamic taint analysis policies to: (i) scan for chains of vulnerable system calls (e.g., to execute code or corrupt the filesystem), and (ii) generate exploits for those that take unmodified attacker data as input. EINSTEIN discovers thousands of vulnerable syscalls in common server applications-well beyond the reach of existing approaches. Moreover, using nginx as a case study, we use EINSTEIN to generate 944 exploits, and we discuss two such exploits that bypass state-of-the-art mitigations. Step 1: Exploit a memory write vulnerability. Step 2: Steer the execution to a gadget's entry point. Step 3: Execute some payload via a gadget chain. (a) Steps in any non-control (or control) data attack. Goal 1: Automatically model an arbitrary memory write vulnerability. Goal 2: Automatically identify an arbitrary gadget entry point. Goal 3: Automatically produce a full gadget chain.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- On Scalable Integrity Checking for Secure Cloud DisksQuinn Burke, Ryan Sheatsley, Rachel King, Owen Hines 等FAST 2025 · 被引用 5 次
- It's a Feature, Not a Bug: Secure and Auditable State Rollback for Confidential Cloud ApplicationsQuinn Burke, Anjo Vahldiek-Oberwagner, Michael Swift, Patrick D. McDanielS&P 2026 · 被引用 2 次
- DirtyFree: Simplified Data-Oriented Programming in the Linux KernelYoochan Lee, Hyuk Kwon, Thorsten HolzNDSS 2026 · 被引用 1 次
- SACK: Systematic Generation of Function Substitution Attacks Against Control-Flow IntegrityZhechang Zhang, Hengkai Ye, Song Liu, Hong HuNDSS 2026 · 被引用 1 次
- Sound and Efficient Generation of Data-Oriented Exploits via Programming Language SynthesisYuxi Ling, Gokul Rajiv, Kiran Gopinathan, Ilya SergeyUSENIX Security 2025
它引用的顶会 Paper21
- VUzzer: Application-aware Evolutionary FuzzingSanjay Rawat, Vivek Jain, Ashish Kumar, Lucian Cojocar 等NDSS 2017 · 被引用 700 次
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 被引用 616 次
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua 等S&P 2016 · 被引用 420 次
- A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary LevelVictor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski 等S&P 2016 · 被引用 227 次
- Debloating Software through Piece-Wise Compilation and LoadingAnh Quach, Aravind Prakash, Lok-Kwong YanUSENIX Security 2018 · 被引用 153 次
相关 Paper
- KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel VulnerabilitiesWei Wu, Yueqi Chen, Xinyu Xing, Wei ZouUSENIX Security 2019 · 被引用 75 次
- Discovering, characterizing and exploiting controllable-copy objects for kernel data-only attacks with CopyKatJakob Koschel, Andrea Mambretti, Alessandro Sorniotti, Pietro Moretto 等USENIX Security 2026
- DynPTA: Combining Static and Dynamic Analysis for Practical Selective Data ProtectionTapti Palit, Jarin Firose Moon, Fabian Monrose, Michalis PolychronakisS&P 2021 · 被引用 48 次
- SpecTaint: Speculative Taint Analysis for Discovering Spectre GadgetsZhenxiao Qi, Qian Feng, Yueqiang Cheng, Mengjia Yan 等NDSS 2021
- Kasper: Scanning for Generalized Transient Execution Gadgets in the Linux KernelBrian Johannesmeyer, Jakob Koschel, Kaveh Razavi, Herbert Bos 等NDSS 2022
