Defeating ROP Through Dynamically Encrypted Return Addresses
Matthew L. White · OhioLink ETD Center (Ohio Library and Information Network) · 2014
Operating systems have been evolving to provide defenses, including Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR), for some common attack vectors.However, as defenses increase, so does the cleverness of attackers.A more recent attack vector seeks to bypass the most common defense mechanisms by needing only to execute instructions that already exist in the program being run.This method, Return Oriented Programming (ROP), has allowed for new exploitation vectors on even the most up-to-date operating systems.A ROP attack is performed by an attacker who first gains control of a program and then executes a series of short instructions (gadgets) that already exist within the running application.This paper introduces a new method to mitigate ROP attacks that removes the control an attacker has in selecting and executing arbitrary portions of code.This is accomplished through the use of dynamic analysis and instrumentation to both identify when a program calls a function and to encrypt the return address that will be used. Average Instructions