شماره ركورد كنفرانس
766
عنوان مقاله
Tiny Jump-Oriented Programming Attack (A Class of Code Reuse Attacks)
عنوان به زبان ديگر
Tiny Jump-Oriented Programming Attack (A Class of Code Reuse Attacks)
پديدآورندگان
Sadeghi AliAkbar نويسنده Iran - Tehran - Amirkabir University of Technology - Department of Computer Engineering and Information Technology , Aminmansour Farzane نويسنده Iran - Tehran - Amirkabir University of Technology - Department of Computer Engineering and Information Technology , Shahriari Hamid Reza نويسنده Iran - Tehran - Amirkabir University of Technology - Department of Computer Engineering and Information Technology
تعداد صفحه
6
كليدواژه
componen , Code Reuse Attacks , Jump Oriented , Programming , TinyJOP , Kernel Trapper Gadget
سال انتشار
1394
عنوان كنفرانس
12 دهمين كنفرانس بين المللي انجمن رمز ايران
زبان مدرك
فارسی
چكيده لاتين
Code reuse attacks such as return oriented
programming and jump oriented programming become the most
popular exploitation methods among attackers. A large number
of practical and non-practical defenses have been proposed that
differ in their overhead, the source code requirement, detection
rate and implementation dependencies. However, a usual aspect
among them is to consider the common behavior of code reuse
attacks, which is the construction of a gadget chain. Therefore,
the implication of a gadget and the minimum size of an attack
chain are a matter of controversy. Conservative or relaxed
thresholds may cause false positive and false negative alarms
respectively. The main contribution of this paper is to provide a
tricky aspect of code reuse techniques, called Tiny Jump-oriented
Programming (Tiny-JOP) that demonstrates the ineffectiveness of
the threshold based detection methods. We demonstrate the
effectiveness of our approach by implementing a sample proof of
concept shell-code and exploiting a real-world buffer overflow
vulnerability in HT Editor 2.0.20.
شماره مدرك كنفرانس
4490565
سال انتشار
1394
از صفحه
1
تا صفحه
6
سال انتشار
1394
لينک به اين مدرک