A Control Flow Integrity Checking Technique Based on Hardware Support
Yang Li, Zibin Dai, Junwei Li · 2018
In this paper, we propose a new hardware-supported lightweight control flow integrity check method in RISC architecture processors, which resists code reuse attacks with negligible performance overhead without extending ISAs or modifying compile. The key technique involves two control flow checking mechanisms. The first one is the liner encryption/decryption operation between PUF response and the instructions at target addresses of call and jmp instructions to defeat JOP attacks. The second one determines whether the return address has been tampered with, thereby resisting the ROP attack, which is based on the secondary encryption authentication of the return address by the hash module. The Mibench benchmark evaluation showed that the proposed method incurs 1.30% runtime overheads on average with no need for as support.