Packed, Printable, and Polymorphic Return-Oriented Programming
Return-oriented programming (ROP) is an attack that has been shown to be able to circumvent W ⊕ X protection. However, it was not clear if ROP can be made as powerful as non-ROP malicious code in other aspects, e.g., be packed to make static analysis difficult, be printable to evade non-ASCII filter...
Saved in:
Main Authors: | , , , |
---|---|
Format: | text |
Language: | English |
Published: |
Institutional Knowledge at Singapore Management University
2011
|
Subjects: | |
Online Access: | https://ink.library.smu.edu.sg/sis_research/2004 https://ink.library.smu.edu.sg/context/sis_research/article/3003/viewcontent/raid11.pdf |
Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Institution: | Singapore Management University |
Language: | English |
id |
sg-smu-ink.sis_research-3003 |
---|---|
record_format |
dspace |
spelling |
sg-smu-ink.sis_research-30032014-02-04T11:54:04Z Packed, Printable, and Polymorphic Return-Oriented Programming LU, Kangjie Zou, Dabi Wen, Weiping GAO, Debin Return-oriented programming (ROP) is an attack that has been shown to be able to circumvent W ⊕ X protection. However, it was not clear if ROP can be made as powerful as non-ROP malicious code in other aspects, e.g., be packed to make static analysis difficult, be printable to evade non-ASCII filtering, be polymorphic to evade signature-based detection, etc. Research in these potential advances in ROP is important in designing counter-measures. In this paper, we show that ROP code could be packed, printable, and polymorphic. We demonstrate this by proposing a packer that produces printable and polymorphic ROP code. It works on virtually any unpacked ROP code and produces packed code that is self-contained. We implement our packer and demonstrate that it works on both Windows XP and Windows 7 platforms. 2011-09-20T07:00:00Z text application/pdf https://ink.library.smu.edu.sg/sis_research/2004 info:doi/10.1007/978-3-642-23644-0_6 https://ink.library.smu.edu.sg/context/sis_research/article/3003/viewcontent/raid11.pdf http://creativecommons.org/licenses/by-nc-nd/4.0/ Research Collection School Of Computing and Information Systems eng Institutional Knowledge at Singapore Management University Return-oriented programming packer printable shellcode polymorphic malware Information Security |
institution |
Singapore Management University |
building |
SMU Libraries |
continent |
Asia |
country |
Singapore Singapore |
content_provider |
SMU Libraries |
collection |
InK@SMU |
language |
English |
topic |
Return-oriented programming packer printable shellcode polymorphic malware Information Security |
spellingShingle |
Return-oriented programming packer printable shellcode polymorphic malware Information Security LU, Kangjie Zou, Dabi Wen, Weiping GAO, Debin Packed, Printable, and Polymorphic Return-Oriented Programming |
description |
Return-oriented programming (ROP) is an attack that has been shown to be able to circumvent W ⊕ X protection. However, it was not clear if ROP can be made as powerful as non-ROP malicious code in other aspects, e.g., be packed to make static analysis difficult, be printable to evade non-ASCII filtering, be polymorphic to evade signature-based detection, etc. Research in these potential advances in ROP is important in designing counter-measures. In this paper, we show that ROP code could be packed, printable, and polymorphic. We demonstrate this by proposing a packer that produces printable and polymorphic ROP code. It works on virtually any unpacked ROP code and produces packed code that is self-contained. We implement our packer and demonstrate that it works on both Windows XP and Windows 7 platforms. |
format |
text |
author |
LU, Kangjie Zou, Dabi Wen, Weiping GAO, Debin |
author_facet |
LU, Kangjie Zou, Dabi Wen, Weiping GAO, Debin |
author_sort |
LU, Kangjie |
title |
Packed, Printable, and Polymorphic Return-Oriented Programming |
title_short |
Packed, Printable, and Polymorphic Return-Oriented Programming |
title_full |
Packed, Printable, and Polymorphic Return-Oriented Programming |
title_fullStr |
Packed, Printable, and Polymorphic Return-Oriented Programming |
title_full_unstemmed |
Packed, Printable, and Polymorphic Return-Oriented Programming |
title_sort |
packed, printable, and polymorphic return-oriented programming |
publisher |
Institutional Knowledge at Singapore Management University |
publishDate |
2011 |
url |
https://ink.library.smu.edu.sg/sis_research/2004 https://ink.library.smu.edu.sg/context/sis_research/article/3003/viewcontent/raid11.pdf |
_version_ |
1770571771902164992 |