GuiDiv: Mitigating Code-reuse Attack in an IoT Cluster Using Guided Control Flow Diversification
Yuanpei Li, Qinglei Zhou, Bin Li, Yan Zhuang · 2023
Code randomization, aka software diversification, is an effective way to mitigate code-reuse attacks. This mechanism diversifies the target software into heterogeneous variants, making a specific attack chain unfeasible for the transformed variants. Enhancing the heterogeneity of these variants is important for this method to reach its expected security level. Additionally, limiting their execution overhead is necessary to ensure the availability of this protection. However, finding the optimal subset among a large number of diversified variants is computationally difficult. This creates a dilemma in software diversification schema where enhancing heterogeneity and reducing execution overhead are both desired.To ensure a determined code quality control in generating software variants, we propose a guided software diversification mechanism (called GuiDiv). GuiDiv formalizes the iterate-used transformations into a branching process of a tree (called DivTree) and introduces an optimization process (called nodemerging) to guide the diversification. The optimizer evaluates the intermediate compilation results using multi-target evaluation functions in each iteration. This process aims to optimize the contribution of structural heterogeneity from redundant instructions, allowing variants with higher structural dissimilarity and lower overhead to have a higher chance of participating in the next iteration. We developed a proof-of-concept compilation module and used OpenSSL as the performance benchmark. In the evaluations, compared to related schemes, GuiDiv can bring higher control flow dissimilarity in most test cases. Regarding the variant heterogeneity, variants generated by GuiDiv exhibit significantly lower execution overhead.