HomeSecurityResearchers bypass ASLR protection

Researchers bypass ASLR protection

A team of scientists from two US universities devised a method of bypassing ASLR (Address Space Layout Randomization) protection through the BTB (Branch Target Buffer), a component included in many modern CPU architectures, such as Intel Haswell processors, which was the processor they used for their research tests.

ASLR protection is a security feature that all major operating systems have and has been part of Windows, Linux, MacOS, iOS, and Android for many years.intel-haswell ASLR

The feature works by taking data objects sent to the CPU for processing and assigning them to a random address space where they are executed internally in the computer's memory (RAM).

Because most “takeover” vulnerabilities rely on corruption of memory data via buffer overflows, an attacker would need to know how to create malicious exploits in order to trick the computer into executing malicious code. To do this, they would need to know the address space that an application uses to execute code inside the computer’s memory. This can be determined quite easily by analyzing the application’s source code.

That's where ASLR comes in, which encrypts memory addresses by holding them in an index. So if ASLR is working properly, malware or exploits will hit the wrong memory locations, leaving the computer safe and sound.

In a paper published this week, a team of computer science experts say they have identified a problem in BTB, a cache system that keeps track of memory locations. Processors that use BTB to speed up processes work much like a browser cache that is typically used to speed up web pages you have already visited.

The technique the researchers describe allows them to retrieve data from the CPU core that contains ASLR index tables, which lets attackers know where a particular application's code is running so they can perfect their exploits.

“The described attack can be carried out in a very short time: only 60 milliseconds are required to collect the required number of samples,” the researchers state in their paper.

The attack requires a special program that has only been tested on a Linux machine with an Intel Haswell processor. However, the researchers say that the same attack should theoretically work on any other operating system, even on KVMs (Kernel Virtual Machines), which are bare-bones operating systems deployed with cloud services.

The three researchers in their paper propose a series of hardware and software fixes that can mitigate these types of attacks. The easiest solution relies on software that requires OS vendors to implement ASLR protection at the code level rather than via data objects.

The research paper, titled Jump Over ASLR: Attacking Branch Predictors to Bypass ASLR, was authored by Dmitry Evtyushkin and Dmitry Ponomarev from the State University of New York and Nael Abu-Ghazaleh from the University of California.

Jump Over ASLR: Attacking Branch Predictors to Bypass ASLR

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS