How to Make ASLR Win the Clone Wars: Runtime Re-Randomization

Kangjie Lu, Stefan Nürnberger, Michael Backes, Wenke Lee · 2016

Existing techniques for memory randomization such as the widely explored Address Space Layout Randomization (ASLR) perform a single, per-process randomization that is applied before or at the process' load-time.The efficacy of such upfront randomizations crucially relies on the assumption that an attacker has only one chance to guess the randomized address, and that this attack succeeds only with a very low probability.Recent research results have shown that this assumption is not valid in many scenarios, e.g., daemon servers fork child processes that inherent the state -and if applicable: the randomization -of their parents, and thereby create clones with the same memory layout.This enables the so-called clone-probing attacks where an adversary repeatedly probes different clones in order to increase its knowledge about their shared memory layout.

Read the paper · More papers on PaperTik