PLaTypus: Restricting Cross-Module Transitions to Mitigate Code-Reuse Attacks
Apostolos Chatzianagnostou, Marcos Bajo, Christian Rossow
摘要
Numerous techniques have been proposed to thwart code reuse attacks, yet practical adoption remains limited due to compatibility and deployment challenges. In the current and foreseeable Intel architecture landscape, the main line of defense against such attacks is Intel CET-a hardwareenforced control-flow integrity mechanism integrated into recent Intel x86-64 CPUs. However, despite its hardware-backed protections and widespread adoption, CET still provides only partial security: it continues to allow hijacked function pointers to invoke arbitrary functions across module boundaries, a capability that remains fundamental to many modern exploits. This paper proposes PLATYPUS, a novel defense on top of Intel CET to address this limitation. PLATYPUS enforces execution jails using lightweight address masking to ensure indirect control transfers remain within module boundaries. Cross-DSO function calls are only permitted via necessary PLT stubs specific to each DSO. The evaluation on our LLVM-based prototype, spanning 19 applications and 16 shared libraries (including glibc), demonstrates that PLATYPUS reduces indirectly accessible cross-DSO functions by over 98 %. Performance testing with complex applications like Nginx and Redis shows that PLATYPUS incurs no more than 0.5 % overhead.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Crashing Through Defenses: Exploiting Segfaults and Chaining Around Intel CETMarcos Bajo, Ritvik Goyal, Apostolos Chatzianagnostou, Christian RossowS&P 2026
- CETIS: Retrofitting Intel CET for Generic and Efficient Intra-process Memory IsolationMengyao Xie, Chenggang Wu, Yinqian Zhang, Jiali Xu 等CCS 2022 · 被引用 14 次
- Hurdle: Securing Jump Instructions Against Code Reuse AttacksChristian DeLozier, Kavya Lakshminarayanan, Gilles Pokam, Joseph DeviettiASPLOS 2020 · 被引用 6 次
- IMIX: In-Process Memory Isolation EXtensionTommaso Frassetto, Patrick Jauernig, Christopher Liebchen, Ahmad-Reza SadeghiUSENIX Security 2018 · 被引用 77 次
- SpecCFI: Mitigating Spectre Attacks using CFI Informed SpeculationEsmaeil Mohammadian Koruyeh, Shirin Haji Amin Shirazi, Khaled N. Khasawneh, Chengyu Song 等S&P 2020 · 被引用 74 次
