引用本文:张正,薛静锋,张静慈,陈田,谭毓安,李元章,张全新.进程控制流完整性保护技术综述.软件学报,2023,34(1):489-508
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 2441次   下载 6719 本文二维码信息
码上扫一扫!
分享到: 微信 更多
进程控制流完整性保护技术综述
张正1, 薛静锋2, 张静慈1, 陈田1, 谭毓安1, 李元章1, 张全新1
1.北京理工大学 计算机学院, 北京 100081;2.北京理工大学 软件学院, 北京 100081
摘要:
控制流劫持攻击利用程序内存漏洞获取程序的控制权, 进而控制程序执行恶意代码, 对系统安全造成极大的威胁. 为了应对控制流劫持攻击, 研究人员提出了一系列的防御手段. 控制流完整性是一种运行时防御方法, 通过阻止进程控制流的非法转移, 来确保控制流始终处于程序要求的范围之内. 近年来, 越来越多的研究致力于解决控制流完整性的相关问题, 例如提出新的控制流完整性方案、新的控制流完整性方案评估方法等. 首先阐述了控制流完整性的基本原理, 然后对现有控制流完整性方案进行了分类, 并分别进行了分析, 同时介绍了现有针对控制流完整性方案的评估方法与评价指标. 最后, 对控制流完整性的未来工作进行了展望, 以期对未来的控制流完整性研究提供参考.
关键词:  控制流完整性  控制流劫持  控制流图  系统安全
DOI:10.13328/j.cnki.jos.006436
分类号:
基金项目:国家自然科学基金(U1936218, 62072037); 之江实验室开放课题(2020LE0AB02)
Survey on Control-flow Integrity Techniques
ZHANG Zheng1, XUE Jing-Feng2, ZHANG Jing-Ci1, CHEN Tian1, TAN Yu-An1, LI Yuan-Zhang1, ZHANG Quan-Xin1
1.School of Computer Science and Technology, Beijing Institute of Technology, Beijing 100081, China;2.School of Software, Beijing Institute of Technology, Beijing 100081, China
Abstract:
Control-flow hijacking attacks exploit memory corruption vulnerabilities to grab control of the program, and then hijack the program to execute malicious code, which brings a great threat to system security. In order to prevent control-flow hijacking attacks, researchers have presented a series of defense methods. Control-flow integrity is a runtime defense method that prevents illegal transfer of process control-flow to ensure that control-flow is always within the range required by the program. In recent years, more and more research works are devoted to solving related problems of control-flow integrity, such as presenting new control-flow integrity schemes, new control-flow integrity scheme evaluation methods, etc. This study explains the basic principles of control flow integrity, and then classifies existing control flow integrity schemes. The existing evaluation methods and evaluation indicators of the control-flow integrity scheme are introduced at the same time. Finally, the thoughts on potential future work on control-flow integrity is summarized, which, hopefully, will provide an outlook of the research direction in the future.
Key words:  control flow integrity  control flow hijacking  control-flow graph  system security

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: