CoDaRR: Continuous Data Space Randomization against Data-Only Attacks

Prabhu Rajasekaran, Stephen J. Crane, David R. Gens, Yeoul Na, Stijn Volckaert, Michael Franz · 2020

The widespread deployment of exploit mitigations such as CFI and shadow stacks are making code-reuse attacks increasingly difficult. This has forced adversaries to consider data-only attacks against which the venerable ASLR remains the primary deployed defense.Data-Space Randomization (DSR) techniques raise the bar against data-only attacks by making it harder for adversaries to inject malicious data flows into vulnerable applications. DSR works by masking memory load and store instructions. Masks are chosen (i) to not interfere with intended data flows and (ii) such that masking likely interferes with unintended flows introduced by malicious program inputs.

Read the paper · More papers on PaperTik