>
Fa   |   Ar   |   En
   dwarf frankenstein is still in your memory: tiny code reuse attacks  
   
نویسنده sadeghi aliakbar ,aminmansour farzane ,shahriari hamidreza
منبع the isc international journal of information security - 2017 - دوره : 9 - شماره : 1 - صفحه:53 -72
چکیده    Code reuse attacks such as return oriented programming and jump oriented programming are the most popular exploitation methods among attackers. a large number of practical and non-practical defenses are proposed that differ in their overhead, the source code requirement, detection rate and implementation dependencies. however, a usual aspect among these methods is consideration of the common behaviour of code reuse attacks, which is the construction of a gadget chain. therefore, the implication of a gadget and the minimum size of an attack chain are a matter of controversy. conservative or relaxed thresholds may cause false positive and false negative alarms, respectively. the main contribution of this paper is to provide a tricky aspect of code reuse techniques, called tiny code reuse attacks (tiny-cra) that demonstrates the ineffectiveness of the threshold based detection methods. we show that with bare minimum assumptions, tiny-cra can reduce the size of a gadget chain in shuch a way that no distinction can be detected between normal behaviour of a program and a code-reuse execution. to do so, we exhibit our tiny-cra primitives and introduce a useful gadget set available in “libc. we demonstrate the effectiveness of our approach by implementing nine different shell-codes and exploiting real-world buffer overflow vulnerability in ht editor 2.0.20.
کلیدواژه software security ,code reuse attacks ,jump oriented programming ,tiny jop ,kernel trapper gadget
آدرس amirkabir university of technology, department of computer engineering and information technology, ایران, amirkabir university of technology, department of computer engineering and information technology, ایران, amirkabir university of technology, department of computer engineering and information technology, ایران
پست الکترونیکی shahriari@aut.ac.ir
 
     
   
Authors
  
 
 

Copyright 2023
Islamic World Science Citation Center
All Rights Reserved