Skip to main navigation Skip to search Skip to main content

An online approach to defeating return-oriented-programming attacks

  • CAS - Institute of Information Engineering
  • Beijing Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Return-oriented programming (ROP) attacks become very popular in recent years, as these attacks can bypass traditional defense mechanisms such as data execution prevention (DEP) effectively. Previous solutions suffer from limitations in that: (1) Some methods need to modify the target programs; (2) Some methods introduce considerable performance cost; (3) Almost all methods could not provide an online protection for the target processes. In this paper, we present OnDrop, an on-the-fly ROP protection system by using the OS internal facilities. Our system is compatible with the existing programs, and its protection layer can be added on demand. The experiments show that OnDrop can detect ROP attacks effectively with a little performance overhead.

Original languageEnglish
Title of host publicationCyberspace Safety and Security - 9th International Symposium, CSS 2017, Proceedings
EditorsWei Wu, Aniello Castiglione, Sheng Wen
PublisherSpringer Verlag
Pages236-247
Number of pages12
ISBN (Print)9783319694702
DOIs
Publication statusPublished - 2017
Event9th International Symposium on Cyberspace Safety and Security, CSS 2017 - Xi'an, China
Duration: 23 Oct 201725 Oct 2017

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume10581 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference9th International Symposium on Cyberspace Safety and Security, CSS 2017
Country/TerritoryChina
CityXi'an
Period23/10/1725/10/17

Keywords

  • On-the-fly
  • Protection
  • Return-oriented programming

Fingerprint

Dive into the research topics of 'An online approach to defeating return-oriented-programming attacks'. Together they form a unique fingerprint.

Cite this