شماره ركورد كنفرانس :
766
عنوان مقاله :
Tiny Jump-Oriented Programming Attack (A Class of Code Reuse Attacks)
عنوان به زبان ديگر :
Tiny Jump-Oriented Programming Attack (A Class of Code Reuse Attacks)
پديدآورندگان :
Sadeghi AliAkbar نويسنده Iran - Tehran - Amirkabir University of Technology - Department of Computer Engineering and Information Technology , Aminmansour Farzane نويسنده Iran - Tehran - Amirkabir University of Technology - Department of Computer Engineering and Information Technology , Shahriari Hamid Reza نويسنده Iran - Tehran - Amirkabir University of Technology - Department of Computer Engineering and Information Technology
تعداد صفحه :
6
كليدواژه :
componen , Code Reuse Attacks , Jump Oriented , Programming , TinyJOP , Kernel Trapper Gadget
سال انتشار :
1394
عنوان كنفرانس :
12 دهمين كنفرانس بين المللي انجمن رمز ايران
زبان مدرك :
فارسی
چكيده لاتين :
Code reuse attacks such as return oriented programming and jump oriented programming become the most popular exploitation methods among attackers. A large number of practical and non-practical defenses have been proposed that differ in their overhead, the source code requirement, detection rate and implementation dependencies. However, a usual aspect among them is to consider the common behavior of code reuse attacks, which is the construction of a gadget chain. Therefore, the implication of a gadget and the minimum size of an attack chain are a matter of controversy. Conservative or relaxed thresholds may cause false positive and false negative alarms respectively. The main contribution of this paper is to provide a tricky aspect of code reuse techniques, called Tiny Jump-oriented Programming (Tiny-JOP) that demonstrates the ineffectiveness of the threshold based detection methods. We demonstrate the effectiveness of our approach by implementing a sample proof of concept shell-code and exploiting a real-world buffer overflow vulnerability in HT Editor 2.0.20.
شماره مدرك كنفرانس :
4490565
سال انتشار :
1394
از صفحه :
1
تا صفحه :
6
سال انتشار :
1394
لينک به اين مدرک :
بازگشت