An online approach to defeating return-oriented-programming attacks

Donghai Tian*, Xiaoqi Jia, Li Zhan, Changzhen Hu, Jingfeng Xue

*此作品的通讯作者

科研成果: 书/报告/会议事项章节会议稿件同行评审

2 引用 (Scopus)

摘要

Return-oriented programming (ROP) attacks become very popular in recent years, as these attacks can bypass traditional defense mechanisms such as data execution prevention (DEP) effectively. Previous solutions suffer from limitations in that: (1) Some methods need to modify the target programs; (2) Some methods introduce considerable performance cost; (3) Almost all methods could not provide an online protection for the target processes. In this paper, we present OnDrop, an on-the-fly ROP protection system by using the OS internal facilities. Our system is compatible with the existing programs, and its protection layer can be added on demand. The experiments show that OnDrop can detect ROP attacks effectively with a little performance overhead.

源语言英语
主期刊名Cyberspace Safety and Security - 9th International Symposium, CSS 2017, Proceedings
编辑Wei Wu, Aniello Castiglione, Sheng Wen
出版商Springer Verlag
236-247
页数12
ISBN(印刷版)9783319694702
DOI
出版状态已出版 - 2017
活动9th International Symposium on Cyberspace Safety and Security, CSS 2017 - Xi'an, 中国
期限: 23 10月 201725 10月 2017

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
10581 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议9th International Symposium on Cyberspace Safety and Security, CSS 2017
国家/地区中国
Xi'an
时期23/10/1725/10/17

指纹

探究 'An online approach to defeating return-oriented-programming attacks' 的科研主题。它们共同构成独一无二的指纹。

引用此