Where's the FEEB? the effectiveness of instruction set randomization
Ana N Sovarel, David Evans, Nathanael Paul · USENIX Security Symposium · 2005
Instruction Set Randomization (ISR) has been proposed as a promising defense against code injection attacks. It defuses all standard code injection attacks since the attacker does not know the instruction set of the target machine. A motivated attacker, however, may be able to circumvent ISR by determining the randomization key. In this paper, we investigate the possibility of a remote attacker successfully determining an ISR key using an incremental attack. We introduce a strategy for attacking ISR-protected servers, develop and analyze two types of attack, and present a technique for packaging the worm with a miniature virtual machine that reduces the number of key bytes an attacker must acquire to 128. Our attacks can break enough key bytes to infect an ISR-protected server in under 7 minutes. Our results provide insights into properties necessary for ISR implementations to be secure.