Hardware Solution for Detection and Prevention of Buffer Overflow Attacks in CPU Micro-architecture
Yan Xiao-lang · Research & Progress of SSE Solid State Electronics · 2006
A new hardware solution for detection and prevention of stack-smashing attacks is proposed.A number is kept as key in CPU to encrypt return address.The cipher return address is inserted between stack frames,and the plain return address is pushed to stack as conventional.If the two return addresses loaded back mismatch when subroutine returns,buffer overflow is then detected and exception is incurred to prevent malicious attack.All the excessive stack operations are implemented by adding specific hardware circuits in CPU.These operations and hardware modification are transparent to software.The performance overhead can be ignored due to parallel execution units in the CPU architecture.