5 ms·
Abstract: > Attacks often succeed by abusing the gap between programand machine-level semantics– for example, by locating asensitive pointer, exploiting a bug
by Hello71 7y ago
Abstract:
> Attacks often succeed by abusing the gap between programand machine-level semantics– for example, by locating asensitive pointer, exploiting a bug to overwrite this sensitivedata, and hijacking the victim program’s execution. In thiswork, we take secure system design on the offensive bycontinuously obfuscating information that attackers needbut normal programs do not use, such as representation ofcode and pointers or the exact location of code and data.Our secure hardware architecture, Morpheus, combines twopowerful protections: ensembles of moving target defensesand churn. Ensembles of moving target defenses randomizekey program values (e.g., relocating pointers and encryptingcode and pointers) which forces attackers to extensivelyprobe the system prior to an attack. To ensure attack probesfail, the architecture incorporates churn to transparently re-randomize program values underneath the running system.With frequent churn, systems quickly become impracticallydifficult to penetrate.We demonstrate Morpheus through a RISC-V-based pro-totype designed to stop control-flow attacks. Each moving target defense in Morpheus uses hardware support to indi-vidually offer more randomness at a lower cost than pre-vious techniques. When ensembled with churn, Morpheusdefenses offer strong protection against control-flow attacks,with our security testing and performance studies revealing:i)high-coverage protection for a broad array of control-flowattacks, including protections for advanced attacks and anattack disclosed after the design of Morpheus, andii)neg-ligible performance impacts (1%) with churn periods up to50 ms, which our study estimates to be at least 5000x fasterthan the time necessary to possibly penetrate Morpheus.