VIPER: Spotting Syscall-Guard Variables for Data-Only Attacks
Hengkai Ye, Song Liu, Zhechang Zhang, Hong Hu
摘要
As control-flow protection techniques are widely deployed, it is difficult for attackers to modify control data, like function pointers, to hijack program control flow. Instead, data-only attacks corrupt security-critical non-control data (critical data), and can bypass all control-flow protections to revive severe attacks. Previous works have explored various methods to help construct or prevent data-only attacks. However, no solution can automatically detect program-specific critical data. In this paper, we identify an important category of critical data, syscall-guard variables, and propose a set of solutions to automatically detect such variables in a scalable manner. Syscall-guard variables determine to invoke security-related system calls (syscalls), and altering them will allow attackers to request extra privileges from the operating system. We propose branch force, which intentionally flips every conditional branch during the execution and checks whether new security-related syscalls are invoked. If so, we conduct dataflow analysis to estimate the feasibility to flip such branches through common memory errors. We build a tool, VIPER, to implement our ideas. VIPER successfully detects 34 previously unknown syscall-guard variables from 13 programs. We build four new data-only attacks on sqlite and v8, which execute arbitrary command or delete arbitrary file. VIPER completes its analysis within five minutes for most programs, showing its practicality for spotting syscall-guard variables.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Practical Data-Only Attack GenerationBrian Johannesmeyer, Asia Slowinska, Herbert Bos, Cristiano GiuffridaUSENIX Security 2024 · 被引用 16 次
- PeTAL: Ensuring Access Control Integrity against Data-only Attacks on LinuxJuhee Kim, Jinbum Park, Yoochan Lee, Chengyu Song 等CCS 2024 · 被引用 6 次
- SACK: Systematic Generation of Function Substitution Attacks Against Control-Flow IntegrityZhechang Zhang, Hengkai Ye, Song Liu, Hong HuNDSS 2026 · 被引用 1 次
- Sound and Efficient Generation of Data-Oriented Exploits via Programming Language SynthesisYuxi Ling, Gokul Rajiv, Kiran Gopinathan, Ilya SergeyUSENIX Security 2025
- SoK: On the Fragility of Memory Error Exploit MitigationsAdriaan Jacobs, Mahmoud Ammar, Stijn VolckaertUSENIX Security 2026
它引用的顶会 Paper17
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 被引用 1,026 次
- CollAFL: Path Sensitive FuzzingShuitao Gan, Chao Zhang, Xiaojun Qin, Xuwen Tu 等S&P 2018 · 被引用 426 次
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua 等S&P 2016 · 被引用 420 次
- MoonShine: Optimizing OS Fuzzer Seed Selection with Trace DistillationShankara Pailoor, Andrew Aday, Suman JanaUSENIX Security 2018 · 被引用 180 次
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 被引用 178 次
相关 Paper
- Protect the System Call, Protect (Most of) the World with BASTIONChristopher Jelesnianski, Mohannad Ismail, Yeongjin Jang, Dan Williams 等ASPLOS 2023 · 被引用 15 次
- JITGuard: Hardening Just-in-time Compilers with SGXTommaso Frassetto, David Gens, Christopher Liebchen, Ahmad-Reza SadeghiCCS 2017 · 被引用 37 次
- Pythia: Compiler-Guided Defense Against Non-Control Data AttacksSharjeel Khan, Bodhisatwa Chatterjee, Santosh PandeASPLOS 2024 · 被引用 2 次
- VIP: Safeguard Value Invariant Property for Thwarting Critical Memory Corruption AttacksMohannad Ismail, Jinwoo Yom, Christopher Jelesnianski, Yeongjin Jang 等CCS 2021 · 被引用 8 次
- A Generic Technique for Automatically Finding Defense-Aware Code Reuse AttacksEdward J. Schwartz, Cory F. Cohen, Jeffrey Gennari, Stephanie SchwartzCCS 2020 · 被引用 8 次
