Skip to main navigation Skip to search Skip to main content

Fast and space-efficient defense against Jump-oriented Programming attacks

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Recently, Jump-oriented Programming (JOP) attack has become widespread in various systems including server, desktop, and smart devices. JOP attack rearranges existing code snippets in program to make gadget sequences, and hijacks control flow of program by chaining and executing gadget sequences consecutively. However, existing defense schemes have limitations such as high execution overhead, high binary size increase overhead, and low applicability. In this paper, to solve these problems, we introduce target shepherding, which is a fast and space-efficient defender against general JOP attack. Our defense scheme generates monitoring code to determine whether the target is legitimate or not just before each indirect jump instruction at compile time, and then checks whether a control flow has been subverted by JOP attack at run time. We achieved very low run-time overhead with very small increase in file size. In our experimental results, the performance overhead is 2.36% and the file size overhead is 5.82% with secure execution.

Original languageEnglish
Title of host publication2015 International Conference on Big Data and Smart Computing, BIGCOMP 2015
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages7-10
Number of pages4
ISBN (Electronic)9781479973033
DOIs
StatePublished - 30 Mar 2015
Event2015 International Conference on Big Data and Smart Computing, BIGCOMP 2015 - Jeju, Korea, Republic of
Duration: 9 Feb 201511 Feb 2015

Publication series

Name2015 International Conference on Big Data and Smart Computing, BIGCOMP 2015

Conference

Conference2015 International Conference on Big Data and Smart Computing, BIGCOMP 2015
Country/TerritoryKorea, Republic of
CityJeju
Period9/02/1511/02/15

Keywords

  • Code Reuse Attack
  • Jump-oriented Programming
  • Return-oriented Programming
  • Software Security

Fingerprint

Dive into the research topics of 'Fast and space-efficient defense against Jump-oriented Programming attacks'. Together they form a unique fingerprint.

Cite this