Overview of the Code-Reuse Attacks Mitigations, and Evaluation using SMAA-2 Approach
Ayman M. El-Zoghby, Mahmoud Said Elsayed, Anca Delia Jurcut, Marianne Amir Azer · Advances in Knowledge-Based Systems Data Science and Cybersecurity · 2025
Exploiting modern software requires sophisticated attack vectors to bypass software protection mechanisms. Code-reuse Attacks (CRAs) are a widely used approach to attack modern software, even after applying memory protection defenses. The underlying vulnerabilities in the software codes or design enable the use of the program’s own code and manipulation of data and code. This paper covers the foundation of memory-based attacks and provides an extensive overview of memory safety issues and exploitation methods, as well as the foundation of control flow attacks and different categories of code-reuse attacks. The focus is on the differences between the various methods employed to mitigate code-reuse attacks. We apply an analysis technique to the covered CRAs to assist in the ranking and evaluation process. The chosen decision-making technique is SMAA-2, which is employed to analyze the mitigation defenses and techniques. This novel approach to evaluating CRAs mitigations helps Decision-makers (DM) in selecting specific CRA techniques over others.