计算机科学与技术

基于静态指令分配的多模块 ROP 自动构造方法

展开
  • 国防科技大学 电子对抗学院,安徽 合肥 230037
黄宁(1990-),男,博士生,主要从事软件漏洞分析研究.

收稿日期: 2017-12-20

  修回日期: 2019-01-20

  网络出版日期: 2019-05-05

基金资助

国家重点研发计划“网络空间安全”重点专项(2017YFB0802905)

Automatic Generation of Multi-modules ROP Based on Static Instructions Assignment

Expand
  • School of Electronic Warfare,National University of Defense Technology,Hefei 230037,Anhui,China 
黄宁(1990-),男,博士生,主要从事软件漏洞分析研究.

Received date: 2017-12-20

  Revised date: 2019-01-20

  Online published: 2019-05-05

Supported by

Supported by the National Key Research and Development Program“Cyberspace Security”(2017YFB0802905) 

摘要

返回导向式编程(ROP)是一种可有效绕过数据执行保护(DEP)机制的技术. 已 有的 ROP 自动构造技术缺少对 ROP 模块转换过程的静态指令分配的优化,导致 ROP 载 荷需占用大量内存空间. 为解决这一问题,基于已有的 ROP 自动构造系统 Q,针对多模块 ROP 的模块转换过程,设计了新的静态指令分配规则 SIA. SIA 通过静态指令分配,构造 中间指令序列;通过动态数据填充,实现 ROP 模块转换过程中的寻址与指针修改. 实验表 明,相比已有技术,通过 SIA 规则构造的多模块 ROP 载荷降低了内存空间占有率,提高了 ROP 载荷的实用性.

本文引用格式

黄宁 黄曙光 黄晖 邓兆琨 . 基于静态指令分配的多模块 ROP 自动构造方法[J]. 华南理工大学学报(自然科学版), 2019 , 47(6) : 31 -38 . DOI: 10.12141/j.issn.1000-565X.180255

Abstract

Return Oriented Programming (ROP) is a kind of technology to bypass the Data Execution Prevention (DEP). Existing technologies for automatic ROP generation can not optimize the progress of instructions assign- ment for modules switching in multi-modules ROP payload,leading to the problem of large amounts of memory space are occupied. In order to solve this problem,a new static instructions assignment rule SIA for ROP modules switching was designed based on the automatic ROP generation system Q. SIA constructs intermediate sequence of instructions by static instructions assignment,and finds the address and modifies the pointers by dynamic data fill- ing. Experimental results show that,compared with the existing technologies,the multi-modules ROP payload gen- erated by SIA needs less memory space so that improve the practicability of ROP.

参考文献

 
文章导航

/