SMP: A New Mechanism to Mitigate Control-Flow Hijacking Attacks
Guorui Lu, Liwei Chen, Gang Shi · 2018
Software code written in low-level languages like C/C++ have many kinds of memory vulnerabilities (e.g., stack overflow, Use-after-free, etc.). Attackers could exploit these vulnerabilities to hijack control-flow and compromise the program. Existing defense mechanisms' (e.g., ASLR, DEP) security guarantee are incomplete, and widely studied defense mechanisms (e.g., CFI) have high overhead and stronger but also limited security guarantees [1]. In this paper, we introduced SMP (Shadow Memory Protection), a new defense mechanism that protects the program's control-flow from being maliciously tampered by protecting critical data in the program (e.g., indirect jump destination address). SMP has a better security-to-overhead ratio than most existing controlflow hijacking protection mechanisms. Experiments showed that SMP mechanism is effective (prevent all attacks in RIPE benchmark) and efficient (3.5% average overhead for C on SPEC CPU2006).