Undermining Information Hiding (and What to Do about It)
Enes Göktas, Robert Gawlik, Benjamin Kollenda, Elias Athanasopoulos, Georgios Portokalidis, Cristiano Giuffrida, Herbert Bos
摘要
In the absence of hardware-supported segmentation, many state-of-the-art defenses resort to "hiding" sensitive information at a random location in a very large address space. This paper argues that information hiding is a weak isolation model and shows that attackers can find hidden information, such as CPI's SafeStacks, in seconds-by means of thread spraying. Thread spraying is a novel attack technique which forces the victim program to allocate many hidden areas. As a result, the attacker has a much better chance to locate these areas and compromise the defense. We demonstrate the technique by means of attacks on Firefox, Chrome, and MySQL. In addition, we found that it is hard to remove all sensitive information (such as pointers to the hidden region) from a program and show how residual sensitive information allows attackers to bypass defenses completely. We also show how we can harden information hiding techniques by means of an Authenticating Page Mapper (APM) which builds on a user-level page-fault handler to authenticate arbitrary memory reads/writes in the virtual address space. APM bootstraps protected applications with a minimum-sized safe area. Every time the program accesses this area, APM authenticates the access operation, and, if legitimate, expands the area on demand. We demonstrate that APM hardens information hiding significantly while increasing the overhead, on average, 0.3% on baseline SPEC CPU 2006, 0.0% on SPEC with SafeStack and 1.4% on SPEC with CPI.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper18
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler 等USENIX Security 2019 · 被引用 247 次
- SoK: Shining Light on Shadow StacksNathan Burow, Xinping Zhang, Mathias PayerS&P 2019 · 被引用 170 次
- Enforcing Unique Code Target Property for Control-Flow IntegrityHong Hu, Chenxiong Qian, Carter Yagemann, Simon Pak Ho Chung 等CCS 2018 · 被引用 142 次
- TypeSan: Practical Type Confusion DetectionIstván Haller, Yuseok Jeon, Hui Peng, Mathias Payer 等CCS 2016 · 被引用 97 次
- Poking Holes in Information HidingAngelos Oikonomopoulos, Elias Athanasopoulos, Herbert Bos, Cristiano GiuffridaUSENIX Security 2016 · 被引用 92 次
它引用的顶会 Paper3
- Dedup Est Machina: Memory Deduplication as an Advanced Exploitation VectorErik Bosman, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaS&P 2016 · 被引用 252 次
- Poking Holes in Information HidingAngelos Oikonomopoulos, Elias Athanasopoulos, Herbert Bos, Cristiano GiuffridaUSENIX Security 2016 · 被引用 92 次
- Enabling Client-Side Crash-Resistance to Overcome Diversification and Information HidingRobert Gawlik, Benjamin Kollenda, Philipp Koppe, Behrad Garmany 等NDSS 2016 · 被引用 77 次
相关 Paper
- SafeHidden: An Efficient and Secure Information Hiding Technique Using Re-randomizationZhe Wang, Chenggang Wu, Yinqian Zhang, Bowen Tang 等USENIX Security 2019 · 被引用 18 次
- Micro-Virtualization Memory Tracing to Detect and Prevent Spraying AttacksStefano Cristalli, Mattia Pagnozzi, Mariano Graziano, Andrea Lanzi 等USENIX Security 2016 · 被引用 10 次
- SEIMI: Efficient and Secure SMAP-Enabled Intra-process Memory IsolationZhe Wang, Chenggang Wu, Mengyao Xie, Yinqian Zhang 等S&P 2020 · 被引用 37 次
- A Call to ARMs: Understanding the Costs and Benefits of JIT Spraying MitigationsWilson Lian, Hovav Shacham, Stefan SavageNDSS 2017 · 被引用 7 次
- PT-Rand: Practical Mitigation of Data-only Attacks against Page TablesLucas Davi, David Gens, Christopher Liebchen, Ahmad-Reza SadeghiNDSS 2017 · 被引用 73 次
