ROPGMN: Effective ROP and variants discovery using dynamic feature and graph matching network

被引:0
|
作者
Niu, Weina [1 ,2 ]
Zhang, Kexuan [1 ]
Yan, Ran [1 ]
Li, Jie [1 ]
Zhang, Yan [2 ]
Zhang, Xiaosong [1 ,2 ]
机构
[1] Univ Elect Sci & Technol China UESTC, Inst Cyber Secur, Sch Comp Sci & Engn, Chengdu 611731, Peoples R China
[2] Univ Elect Sci & Technol China, Shenzhen Inst Adv Study, Shenzhen 518110, Peoples R China
基金
美国国家科学基金会;
关键词
Return oriented programming; ROP variant attacks; Execution flow; Multiple filtering; Graph matching network; Attribution execution flow graph;
D O I
10.1016/j.future.2024.107567
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Return Oriented Programming (ROP) is one of the most challenging threats to operating systems. Traditional detection and defense techniques for ROP such as stack protection, address randomization, compiler optimization, control flow integrity, and basic block thresholds have certain limitations inaccuracy or efficiency. At the same time, they cannot effectively detect ROP variant attacks, such as COP, COOP, JOP. In this paper, we propose a novel ROP and its variants detection approach that first filters the normal execution flow according to four strategies provided and then adopts Graph Matching Network (GMN) to determine whether there is ROP or its variant attack. Moreover, we developed a prototype named ROPGMN with shared memory to solve cross-language and cross-process problems. Using real-world vulnerable programs and constructed programs with dangerous function calls, we conduct extensive experiments with 6 ROP detectors to evaluate ROPGMN. The experimental results demonstrate the effectiveness of ROPGMN in discovering ROPs and their variant attacks with low performance overhead.
引用
收藏
页数:13
相关论文
共 50 条
  • [41] An Accurate Scene Segmentation Method Based on Graph Analysis Using Object Matching and Audio Feature
    Yamamoto, Makoto
    Haseyama, Miki
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2009, E92A (08) : 1883 - 1891
  • [42] Matching document pairs using multi-feature semantic fusion based on knowledge graph
    Chen Y.
    Zhang Z.
    Huang X.
    Xiang X.
    He Z.
    Zhongnan Daxue Xuebao (Ziran Kexue Ban)/Journal of Central South University (Science and Technology), 2023, 54 (08): : 3122 - 3131
  • [43] Vehicle Classification Using AKAZE and Feature Matching Approach and Artificial Neural Network
    Bedruz, Rhen Anjerome R.
    Fernando, Arvin
    Bandala, Argel
    Sybingco, Edwin
    Dadios, Elmer
    PROCEEDINGS OF TENCON 2018 - 2018 IEEE REGION 10 CONFERENCE, 2018, : 1824 - 1827
  • [44] Graph Convolutional Network Using a Reliability-Based Feature Aggregation Mechanism
    Wang, Yanling
    Li, Cuiping
    Zhang, Jing
    Ni, Peng
    Chen, Hong
    DATABASE SYSTEMS FOR ADVANCED APPLICATIONS (DASFAA 2020), PT I, 2020, 12112 : 536 - 552
  • [45] Hyperspectral image classification using feature fusion fuzzy graph broad network
    Chu, Yonghe
    Cao, Jun
    Ding, Weiping
    Huang, Jiashuang
    Ju, Hengrong
    Cao, Heling
    Liu, Guangen
    INFORMATION SCIENCES, 2025, 689
  • [46] IMBALANCED HISTOPATHOLOGY IMAGE CLASSIFICATION USING DEEP FEATURE GRAPH ATTENTION NETWORK
    Cong, Cong
    Yang, Yixing
    Liu, Sidong
    Pagnucco, Maurice
    Song, Yang
    2022 IEEE INTERNATIONAL SYMPOSIUM ON BIOMEDICAL IMAGING (IEEE ISBI 2022), 2022,
  • [47] Spatiotemporal fuzzy-graph convolutional network model with dynamic feature encoding for traffic forecasting
    Zhang, Shuai
    Chen, Yong
    Zhang, Wenyu
    Knowledge-Based Systems, 2021, 231
  • [48] Spatiotemporal fuzzy-graph convolutional network model with dynamic feature encoding for traffic forecasting
    Zhang, Shuai
    Chen, Yong
    Zhang, Wenyu
    KNOWLEDGE-BASED SYSTEMS, 2021, 231
  • [49] Social Spam Discovery using Bayesian Network Classifiers based on Feature Extractions
    Park, Dae-Ha
    Cho, Eun-Ae
    On, Byung-Won
    2013 12TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2013), 2013, : 1808 - 1811
  • [50] A heterogeneous graph neural network with automatic discovery of effective metapaths for drug-target interaction prediction
    Zhang, Menglong
    Hong, Yue
    Shen, Lian
    Xu, Shiyu
    Xu, Yanni
    Zhang, Xinyi
    Liu, Juan
    Liu, Xiangrong
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2024, 160 : 283 - 294