DocumentCode :
2390573
Title :
A dynamic detection method against ROP and JOP
Author :
Huang, ZhiJun ; Zheng, Tao ; Shi, Yunxiu ; Li, Ang
Author_Institution :
Software Inst., Nanjing Univ., Nanjing, China
fYear :
2012
fDate :
19-20 May 2012
Firstpage :
1072
Lastpage :
1077
Abstract :
As the proposition of the idea of Return-Oriented Programming (ROP), programs will face new challenges from viruses, and many of current defense measures will be ineffective. With fine granularity, covert virus features, deliberate and sophisticated construction and rare static characteristics, ROP attack can circumvent many traditional defense measures and its variant Jump-Oriented Programming (JOP) attack makes lots of current special ROP defense tools lose their effects. Under this circumstance, it´s imperative to discover the dynamic features of ROP exploits. At this time, bringing in the technology of Dynamic Binary Instrumentation (DBI) provides powerful support for dynamic analysis of ROP attack. In this paper, we will introduce a defense measure to ROP attack. By identifying malicious program execution flow and restricting the function call specification of general program libraries, we will prevent the turning-complete features of ROP attack. Our detection method can restrain malicious use of shared libraries by ROP and defend a large part of ROP attacks.
Keywords :
object-oriented programming; security of data; DBI; JOP; ROP attack; call specification function; current defense measurement; dynamic analysis; dynamic binary instrumentation; dynamic detection method; jump oriented programming; malicious program execution flow; program libraries; rare static characteristics; return oriented programming; sophisticated construction; Aerospace electronics; Instruments; Kernel; Law; Libraries; Linux; Characteristic Detection; Control Flow; Dynamic Binary Instrumentation; Jump-Oriented Programming; Program Security; Return-Oriented Programming; Turning-Complete;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Systems and Informatics (ICSAI), 2012 International Conference on
Conference_Location :
Yantai
Print_ISBN :
978-1-4673-0198-5
Type :
conf
DOI :
10.1109/ICSAI.2012.6223219
Filename :
6223219
Link To Document :
بازگشت