G-free: Defeating return-oriented programming through gadget-less binaries
Proceedings - Annual Computer Security Applications Conference, ACSAC
MetadataShow full item record
Please cite this item using this persistent URLhttp://hdl.handle.net/11693/28479
Despite the numerous prevention and protection mechanisms that have been introduced into modern operating systems, the exploitation of memory corruption vulnerabilities still represents a serious threat to the security of software systems and networks. A recent exploitation technique, called Return-Oriented Programming (ROP), has lately attracted a considerable attention from academia. Past research on the topic has mostly focused on refining the original attack technique, or on proposing partial solutions that target only particular variants of the attack. In this paper, we present G-Free, a compiler-based approach that represents the first practical solution against any possible form of ROP. Our solution is able to eliminate all unaligned free-branch instructions inside a binary executable, and to protect the aligned free-branch instructions to prevent them from being misused by an attacker. We developed a prototype based on our approach, and evaluated it by compiling GNU libc and a number of real-world applications. The results of the experiments show that our solution is able to prevent any form of return-oriented programming. © 2010 ACM.
- Conference Paper 2294
Showing items related by title, author, creator and subject.
Sensoy, A. (2013)We study the time-varying efficiency of nineteen members of the Federation of Euro-Asian Stock Exchanges (FEAS - an international organization comprising the main stock exchanges in Eastern Europe, the Middle East and ...
Berument, H.; Ceylan, N. B. (Elsevier, 2012-09)This paper assesses the effects of domestic soccer teams' performances against foreign rivals on stock market returns as well as on the return-volatility relationship. Data from Chile, Spain, Turkey and the United Kingdom ...
Berument, M.; Ceylan, N.; Onar, B. (2013)We hypothesize that results of football (soccer) teams affect the risk perception of people. People choose riskier investments after a win and less risky investments after a loss; this leads to higher (lower) returns in ...