CrashROP: A Real-Time ROP Attack Detection Method Based on Crash Context Analysis

Wanzhi Zhang · 2025

With the widespread adoption of Data Execution Prevention (DEP), attacks targeting memory corruption vulnerabilities have shifted from code injection to Return-Oriented Programming (ROP)-based code reuse. Existing detection methods face limitations due to trade-offs between granularity and efficiency (high overhead for instruction-level detection, high false negatives for system-call-level detection) and insufficient crash context. This paper proposes CrashROP, which deploys fine-grained randomization defenses and captures${1 5}$crash-context indicators to construct real-world ROP crash instances. Experiments demonstrate its precision in identifying ROP patterns across standard test suites, real-world exploits, and CTF challenges, with validated specificity against non-ROP attacks. A crash exploitability assessment model is further introduced, offering new insights for real-time detection of unknown vulnerabilities and crash root-cause analysis.

Read the paper · More papers on PaperTik