Multi-variant execution: run-time defense against malicious code injection attacks

Michael Franz, Babak Salamat · 2009

The number and complexity of attacks are increasing. This growth necessitates proper defense mechanisms. Intrusion detection systems have an important role in detecting and disrupting attacks before they can compromise software. Multi-variant execution is an intrusion detection mechanism that executes several slightly different versions or variants of the same program in lockstep. The variants are built to have identical behavior under normal execution conditions. However, when the variants are under attack, there are detectable differences in their execution behavior. At run time, a monitor compares the behavior of the variants at certain synchronization points and raises an alarm when a discrepancy is detected. We present a monitoring mechanism that does not need any kernel privileges to supervise the variants. As a result, the monitor runs entirely in user space. Modern operating systems guarantee that a process can only modify its own process space and needs to invoke a system call to have outside effects. Therefore, injected attack code cannot damage the system without invoking a system call. Our monitor synchronizes the variants at every system call and ensures that all the variants invoke the same system call with equivalent arguments. Asynchronous signals, scheduling of multi-threaded or multi-process applications, time, random numbers, file descriptors, and process IDs can cause the monitor to observe different sequences of system calls or varying arguments in the variants. This causes false alarms. We provide solutions to remove these false alarms in multi-variant execution. Mechanisms to improve performance of the monitor and efficient methods to transfer data between the monitor and variants are also presented. Variation techniques to generate program variants are studied. We also describe a novel technique to generate program variants that use a stack that grows in reverse direction in contrast to the native stack growth direction of hardware. Such program variants, when executed along with conventional executables in a multi-variant environment, allow detection of stack-based buffer overflow attacks. Our experiments show that the multi-variant execution technique is effective in detecting and preventing code injection attacks. The empirical results demonstrate that multi-variant execution has small performance overhead when deployed on multi-core processors.

Read the paper · More papers on PaperTik