Analyzing control flow integrity with LLVM-CFI

Paul Muntean, Matthias Neumayer, Zhiqiang Lin, Gang Tan, Jens Großklags, Claudia Margot Eckert · 2019

Control-flow hijacking attacks are used to perform malicious computations. Current solutions for assessing the attack surface after a control flow integrity (CFI) policy was applied can measure only indirect transfer averages in the best case without providing any insights w.r.t. the absolute calltarget reduction per callsite, and gadget availability. Further, tool comparison is underdeveloped or not possible at all. CFI has proven to be one of the most promising protections against control flow hijacking attacks, thus many efforts have been made to improve CFI in various ways. However, there is a lack of systematic assessment of existing CFI protections.

Read the paper · More papers on PaperTik