Executable Program Code Segment Address Randomization

Jian Lin, Yu-Dong Guo, Yujia Man, Shao-Huang Zhou · 2015

In Linux Address Space layout Randomization, not all memory addresses are random. Executable Program is still loaded to a static address, so an attacker can do code reuse attack by using gadgets in executable program code segment. To improve the weaken ASLR, this paper proposes and implements a new protection method named EPCSAR (Executable Program Code Segment Address Randomization). Taking advantage of static analysis results of IDA, EPCSAR used an IDA plugin to identify the instructions needing relocation in the ELF executable program. By modifying the ELF loader, EPCSAR mapped the executable program code segment into a random address. Evaluation shows the EPCSAR can defense the code reuse attack using gadgets in static region, and only has low runtime overhead of 1.31%.

Read the paper · More papers on PaperTik