TY - GEN
T1 - ROP payload detection using speculative code execution
AU - Polychronakis, Michalis
AU - Keromytis, Angelos D.
PY - 2011
Y1 - 2011
N2 - The prevalence of code injection attacks has led to the wide adoption of exploit mitigations based on nonexecutable memory pages. In turn, attackers are increasingly relying on return-oriented programming (ROP) to bypass these protections. At the same time, existing detection techniques based on shellcode identification are oblivious to this new breed of exploits, since attack vectors may not contain binary code anymore. In this paper, we present a detection method for the identification of ROP payloads in arbitrary data such as network traffic or process memory buffers. Our technique speculatively drives the execution of code that already exists in the address space of a targeted process according to the scanned input data, and identifies the execution of valid ROP code at runtime. Our experimental evaluation demonstrates that our prototype implementation can detect a broad range of ROP exploits against Windows applications without false positives, while it can be easily integrated into existing defenses based on shell-code detection.
AB - The prevalence of code injection attacks has led to the wide adoption of exploit mitigations based on nonexecutable memory pages. In turn, attackers are increasingly relying on return-oriented programming (ROP) to bypass these protections. At the same time, existing detection techniques based on shellcode identification are oblivious to this new breed of exploits, since attack vectors may not contain binary code anymore. In this paper, we present a detection method for the identification of ROP payloads in arbitrary data such as network traffic or process memory buffers. Our technique speculatively drives the execution of code that already exists in the address space of a targeted process according to the scanned input data, and identifies the execution of valid ROP code at runtime. Our experimental evaluation demonstrates that our prototype implementation can detect a broad range of ROP exploits against Windows applications without false positives, while it can be easily integrated into existing defenses based on shell-code detection.
UR - https://www.scopus.com/pages/publications/84855846511
U2 - 10.1109/MALWARE.2011.6112327
DO - 10.1109/MALWARE.2011.6112327
M3 - Conference contribution
AN - SCOPUS:84855846511
SN - 9781467300339
T3 - Proceedings of the 2011 6th International Conference on Malicious and Unwanted Software, Malware 2011
SP - 58
EP - 65
BT - Proceedings of the 2011 6th International Conference on Malicious and Unwanted Software, Malware 2011
T2 - 6th International Conference on Malicious and Unwanted Software, Malware 2011
Y2 - 18 October 2011 through 19 October 2011
ER -