Defeating Code-Reuse Attacks with Binary Instrumentation

Nader Ammari · PolyPublie (École Polytechnique de Montréal) · 2018

La programmation orientee retour (ROP) est une technique par laquelle un attaquant peut introduire un comportement arbitraire dans un programme vulnerable. ROP est actuellement l’un des moyens les plus efficaces pour contourner les dispositifs de protection modernes. Ce type d’attaque a connu un essor phenomenal au cours des cinq dernieres annees. Les techniques utilisees pour se proteger contre ce type d’exploit generent un taux de faux negatif eleve car elles sont facilement contournables. De plus, elles ont tendance a ajouter une surcharge importante sur le programme qu’elles protegent. Dans la premiere partie de ce travail, nous avons etudie ces solutions proposees ou utilisees pour detecter ou attenuer les attaques ROP. Dans la deuxieme partie, nous presentons une nouvelle approche pour detecter les attaques ROP lors de l’execution. Cette partie vise a presenter nos Indicateurs de Compromis (IOC) qui pourraient etre utilises pour ameliorer le taux de detection des attaques RDP. Nous avons egalement propose une technique de mesure permettant de mesurer ces indicateurs lors de l’execution en utilisant des techniques d’instrumentation dynamique de binaires (Dynamic Binary Instrumentation). Nos indicateurs proposes essaient d’identifier une attaque au moment de l’execution en verifiant la presence de certaines caracteristiques. Cette approche permet de detecter les attaques ROP sans compter sur toute autre information complementaire comme le code source ou le support du compilateur. La derniere partie de ce travail couvre le sujet de la phase experimentale, plus precisement, le prototype realise dans le but de prouver l’efficacite de nos indicateurs proposes ainsi que la technique de mesure proposee. Les resultats de cette phase experimentale montrent que seuls les deux premiers indicateurs sont capables de detecter les attaques ROP. ----------ABSTRACT: Return Oriented Programming (ROP) is a technique by which an attacker can induce arbitrary behavior inside a vulnerable program without injecting a malicious code. It is presently one of the most effective ways to bypass modern protection mechanisms such as Data Execution Prevention (DEP) which prevents attackers from executing the malicious code already injected into the memory. ROP is also considered as one of the most flexible attacks, its level of flexibility, unlike other attacks, reaches the Turing completeness. The tremendous success of ROP attacks made the headlines in the cybersecurity space, they became one of the top security concerns and one of the most powerful cross-platform weapons. Several efforts have been undertaken to study this threat and to propose better defence mechanisms (mitigation or prevention), yet the majority of them are not deeply reviewed nor officially implemented. Furthermore, similar studies show that the techniques proposed to prevent ROP-based exploits usually yield a high false-negative rate and a higher false-positive rate, not to mention the overhead that they introduce into the protected program. The first part of this research work aims at providing an in-depth analysis of the currently available anti-ROP solutions (deployed and proposed), focusing on inspecting their defense logic and summarizing their weaknesses and problems. The second part of this work aims at introducing our proposed Indicators Of Compromise (IOC) that could be used to improve the detection rate of ROP attacks. The three suggested indicators could detect these attacks at run-time by checking the presence of some futures during the execution of the targeted program. We also proposed a measurement technique that allows measuring these indicators at run-time. The last part of this work covers the subject of the experimental phase. More specifically, the Proof of Concept performed with the objective of proving the effectiveness of our proposed indicators, as well as the proposed measurement technique. The results of this experimental phase show that only the first two indicators are able to detect ROP attacks. Another important finding was about the non-expected ROP features discovered and visualized during the experiment. These features could be used to strengthen our indicators in future works.

Read the paper · More papers on PaperTik