• DocumentCode
    3097203
  • Title

    Surgically Returning to Randomized lib(c)

  • Author

    Roglia, Giampaolo Fresi ; Martignoni, Lorenzo ; Paleari, Roberto ; Bruschi, Danilo

  • Author_Institution
    Dipt. di Inf. e Comun., Univ. degli Studi di Milano, Milan, Italy
  • fYear
    2009
  • fDate
    7-11 Dec. 2009
  • Firstpage
    60
  • Lastpage
    69
  • Abstract
    To strengthen systems against code injection attacks, the write or execute only policy (W¿X) and address space layout randomization (ASLR) are typically used in combination. The former separates data and code, while the latter randomizes the layout of a process. In this paper we present a new attack to bypass W¿X and ASLR. The state-of-the-art attack against this combination of protections is based on brute-force, while ours is based on the leakage of sensitive information about the memory layout of the process. Using our attack an attacker can exploit the majority of programs vulnerable to stack-based buffer overflows surgically, i.e., in a single attempt. We have estimated that our attack is feasible on 95.6% and 61.8% executables (of medium size) for Intel x86 and x86-64 architectures, respectively. We also analyze the effectiveness of other existing protections at preventing our attack. We conclude that position independent executables (PIE) are essential to complement ASLR and to prevent our attack. However, PIE requires recompilation, it is often not adopted even when supported, and it is not available on all ASLR-capable operating systems. To overcome these limitations, we propose a new protection that is as effective as PIE, does not require recompilation, and introduces only a minimal overhead.
  • Keywords
    analogue storage; Intel x86; Intel x86-64 architectures; address space layout randomization; information sensitivity; memory layout; position independent executables; randomized lib; stack-based buffer overflows; Application software; Buffer overflow; Computer crashes; Computer security; Entropy; Libraries; Operating systems; Protection; Runtime; Surgery;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2009. ACSAC '09. Annual
  • Conference_Location
    Honolulu, HI
  • ISSN
    1063-9527
  • Print_ISBN
    978-0-7695-3919-5
  • Type

    conf

  • DOI
    10.1109/ACSAC.2009.16
  • Filename
    5380519