中国科学院机构知识库网格
Chinese Academy of Sciences Institutional Repositories Grid
HyperCrop: A Hypervisor-Based Countermeasure for Return Oriented Programming

文献类型:会议论文

作者Jun Jiang ; Xiaoqi Jia ; Dengguo Feng ; Shengzhi Zhang ; Peng Liu
出版日期2011-11
会议名称International Conference on Information and Communications Security
会议日期2011/11/23-2011/11/26
会议地点Friendship Hotel, Haidian District, Beijing, China
关键词Return oriented programming Hypervisor-based security Hardware assisted virtualization
中文摘要
Return oriented programming (ROP) has recently caught great attention of both academia and industry. It reuses existing binary code instead of injecting its own code and is able to perform arbitrary computation due to its Turing-completeness. Hence, It can successfully bypass state-of-the-art code integrity mechanisms such as NICKLE and SecVisor. In this paper, we present HyperCrop, a hypervisor-based approach to counter such attacks. Since ROP attackers extract short instruction sequences ending in ret called “gadgets” and craft stack content to “chain” these gadgets together, our method recognizes that the key characteristics of ROP is to fill the stack with plenty of addresses that are within the range of libraries (e.g. libc). Accordingly, we inspect the content of the stack to see if a potential ROP attack exists. We have implemented a proof-of-concept system based on the open source Xen hypervisor. The evaluation results exhibit that our solution is effective and efficient.
收录类别CPCI(ISTP) ; EI
合作状况国际
会议网址http://link.springer.com/chapter/10.1007%2F978-3-642-25243-3_29
会议录Lecture Notes in Computer Science, 2011, Volume 7043/2011 (Proceedings of the 13th International Conference on Information and Communications Security)
会议录出版者Springer-Verlag
学科主题数据安全与计算机安全 ; 计算机系统设计 ; 操作系统与操作环境 ; 程序设计及其语言 ; 编译系统 ; 软件工程
会议录出版地Berlin Heidelberg
语种英语
ISSN号0302-9743
ISBN号978-3-642-25242-6
源URL[http://ir.iscas.ac.cn/handle/311060/14506]  
专题软件研究所_信息安全国家重点实验室_会议论文
推荐引用方式
GB/T 7714
Jun Jiang,Xiaoqi Jia,Dengguo Feng,et al. HyperCrop: A Hypervisor-Based Countermeasure for Return Oriented Programming[C]. 见:International Conference on Information and Communications Security. Friendship Hotel, Haidian District, Beijing, China. 2011/11/23-2011/11/26.http://link.springer.com/chapter/10.1007%2F978-3-642-25243-3_29.

入库方式: OAI收割

来源:软件研究所

浏览0
下载0
收藏0
其他版本

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。