VScape: Assessing and Escaping Virtual Call Protections
Kaixiang Chen, Chao Zhang, Tingting Yin, Xingman Chen, Lei Zhao
摘要
Many control-flow integrity (CFI) solutions have been proposed to protect indirect control transfers (ICT), including C++ virtual calls. Assessing the security guarantees of these defenses is thus important but hard. In practice, for a (strong) defense, it usually requires great manual efforts to assess whether it could be bypassed, when given a specific (weak) vulnerability. Existing automated exploit generation solutions, which are proposed to assess the exploitability of vulnerabilities, have not addressed this issue yet. In this paper, we point out that a wide range of virtual call protections, which do not break the C++ ABI (application binary interface), are vulnerable to an advanced attack COOPLUS, even if the given vulnerabilities are weak. Then, we present a solution VScape to assess the effectiveness of virtual call protections against this attack. We developed a prototype of VScape, and utilized it to assess 11 CFI solutions and 14 C++ applications (including Firefox and PyQt) with known vulnerabilities. Results showed that real-world applications have a large set of exploitable virtual calls, and VScape could be utilized to generate working exploits to bypass deployed defenses via weak vulnerabilities.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Control Flow and Pointer Integrity Enforcement in a Secure Tagged ArchitectureRavi Theja Gollapudi, Gokturk Yuksek, David Demicco, Matthew Cole 等S&P 2023
- CCTAG: Configurable and Combinable Tagged ArchitectureZhanpeng Liu, Yi Rong, Chenyang Li, Wende Tan 等NDSS 2025
- AlphaEXP: An Expert System for Identifying Security-Sensitive Kernel ObjectsRuipeng Wang, Kaixiang Chen, Chao Zhang, Zulie Pan 等USENIX Security 2023
它引用的顶会 Paper16
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua 等S&P 2016 · 被引用 420 次
- A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary LevelVictor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski 等S&P 2016 · 被引用 227 次
- Block Oriented Programming: Automating Data-Only AttacksKyriakos K. Ispoglou, Bader AlBassam, Trent Jaeger, Mathias PayerCCS 2018 · 被引用 143 次
- Enforcing Unique Code Target Property for Control-Flow IntegrityHong Hu, Chenxiong Qian, Carter Yagemann, Simon Pak Ho Chung 等CCS 2018 · 被引用 142 次
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris 等NDSS 2016 · 被引用 141 次
相关 Paper
- Finding Cracks in Shields: On the Security of Control Flow Integrity MechanismsYuan Li, Mingzhe Wang, Chao Zhang, Xingman Chen 等CCS 2020 · 被引用 32 次
- TypeSqueezer: When Static Recovery of Function Signatures for Binary Executables Meets Dynamic AnalysisZiyi Lin, Jinku Li, Bowen Li, Haoyu Ma 等CCS 2023 · 被引用 7 次
- CFIXX: Object Type Integrity for C++Nathan Burow, Derrick Paul McKee, Scott A. Carr, Mathias PayerNDSS 2018 · 被引用 56 次
- SACK: Systematic Generation of Function Substitution Attacks Against Control-Flow IntegrityZhechang Zhang, Hengkai Ye, Song Liu, Hong HuNDSS 2026 · 被引用 1 次
- A Generic Technique for Automatically Finding Defense-Aware Code Reuse AttacksEdward J. Schwartz, Cory F. Cohen, Jeffrey Gennari, Stephanie SchwartzCCS 2020 · 被引用 8 次
