LsStk: Lightweight solution to preventing Stack from buffer overflow vulnerability
Muhammad Ahsan, Muhammad Ali · 2023
Buffer overflow is a significant vulnerability in computer systems, and despite numerous techniques and approaches proposed to protect programs from exploitation, many existing software and hardware-based prevention mechanisms have proven ineffective in mitigating this threat. The presented study introduces a lightweight prevention technique (LsStk). The approach involves implementing an encryption algorithm to safeguard the function return address, making it resilient to exploitation by adversaries. The algorithm integrated at the compiler level, utilizes epilogue and prologue functions to encrypt the return address and protect it from adversarial tampering. Given its minimal footprint, the solution is well-suited for adaptation in embedded IoT (Internet of Things) devices.To evaluate the effectiveness of our proposed technique, we conducted a statistical analysis using various 32-bit servers. We compared the performance of our method with existing prevention mechanisms. Our approach is designed to be adaptable at both the hardware CPU architecture level and as a software-level patch for the GCC compiler. Our analysis leads to the conclusion that our proposed technique significantly enhances security against such attacks.