Secure Call and Return Instructions for Mimicry Attack Detection
Yuuki Tominaga, Takehiro Kashiyama, Eiji Takimoto, Hiroaki Kuwabara, Koichi Mouri, Shoichi Saito, Tetsutaro Uehara, Yoshitoshi Kunieda · 2012
There are many methods to detect buffer overflow using host-based intrusion detection systems or compiler extensions. Some attacks, however, can avoid these defense systems. 'Mimicry Attacks' is one of such attacks. In this paper, we propose a novel method to detect Mimicry Attacks. Our proposed method is able to detect invalid control data (frame pointer and return address on the call stack) overwritten by Mimicry Attacks. To achieve this detection, we extend call and return instructions with our original saving and checking processes respectively. The saving process, which is invoked before called function starts, saves the control data to the invulnerable area. The checking process, which is invoked after called function finishes, compares the saved and real control data. We have implemented our proposed method as software simulation and evaluated its time overhead. The percentage of the processing time for proposed method in each total execution time of gzip, Apache HTTP Server and we are 2.53%, 71.10% and 94.83% respectively.