Lune

NDSS2026顶会

SACK: Systematic Generation of Function Substitution Attacks Against Control-Flow Integrity

Zhechang Zhang, Hengkai Ye, Song Liu, Hong Hu

2026年份
1被引次数

摘要

—Control-flow integrity (CFI) is a widely adopted defense against control-flow hijacking attacks, designed to restrict indirect control transfers to a set of legitimate targets. However, even under a precise static CFI policy, attackers can still hijack control flow through function substitution attacks (S UB attacks), by replacing one valid target with another that remains within the allowed set. While prior work has demonstrated the feasibility of such attacks through manual construction, no approach constructs them systematically, scalably, and in an end-to-end manner. In this work, we present S ACK , the first systematic framework for automatically constructing S UB attacks at scale. S ACK collects triggered indirect call targets from benign executions and synthe-sizes security oracles with the assistance of a large language model. It then automatically performs target substitutions and leverages security oracles to detect security violations, while ensuring that execution strictly adheres to precise CFI policies. We apply S ACK to seven widely used applications and successfully construct 419 S UB attacks that compromise critical security features. We further develop five end-to-end exploits based on historical bugs in SQLite3, V8 and Nginx, enabling arbitrary command execution or authentication bypass. Our results demonstrate that S ACK provides a scalable and automated pipeline capable of uncovering large numbers of end-to-end attacks across diverse applications.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper38

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖