skip to main content
10.1145/1229285.1229338acmconferencesArticle/Chapter ViewAbstractPublication Pagesasia-ccsConference Proceedingsconference-collections
Article

A framework for diversifying windows native APIs to tolerate code injection attacks

Published:20 March 2007Publication History

ABSTRACT

We present a framework to prevent code injection attacks in MS Windows using Native APIs in the operating system. By adopting the idea of diversity, this approach is implemented in a two-tier framework. The first tier permutes the Native API dispatch ID number so that only the Native API calls from legitimate sources are executed. The second tier provides an authentication process in case an attacker guesses the first-tier permutation order. The function call stack is back-traced to verify whether the original caller's return address resides within the legitimate process. The process is terminated and an alert is generated when an attack is suspected. Experiments indicate that our approach poses no significant overhead.

References

  1. Bastard disassembler, http://bastard.sourceforge.net/.Google ScholarGoogle Scholar
  2. S. Bhatkar, D. DuVarney, and R. Sekar. Address obfuscation: An efficient approach to combat a broad range of memory error exploits. USENIX Security Symposium, 12(2):291--301, August 2003. Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. S. Forrest, A. Somayaji, and D. H. Ackley. Building diverse computer systems. In Workshop on Hot Topics in Operating Systems, pages 67--72, 1997. Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. J.Xu, Z. Kalbarczyk, and R. K. Iyer. Transparent runtime randomization for security. Proceedings of 22nd Symposium on Reliable and Distributed Systems (SRDS), October 2003.Google ScholarGoogle Scholar
  5. G. S. Kc, A. D. Keromytis, and V. Prevelakis. Countering Code-Injection Attacks With Instruction-Set Randomization. In Proceedings of the ACM Computer and Communications Security (CCS) Conference, pages 272--280, October 2003. Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. C. Linn, M. Rajagopalan, S. Baker, C. Collberg, H. Hartman, and S. Debray. Protecting against unexpected system calls. Proceedings of the USENIX Security, pages 239--254, 2005. Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. M. Rajagopalan, M. Hiltunen, T. Jim, and R. Schlichting. Authenticated system calls. International Conference on Dependable Systems and Networks(DSN '05), pages 358--367, 2005. Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. A framework for diversifying windows native APIs to tolerate code injection attacks

        Recommendations

        Comments

        Login options

        Check if you have access through your login credentials or your institution to get full access on this article.

        Sign in
        • Published in

          cover image ACM Conferences
          ASIACCS '07: Proceedings of the 2nd ACM symposium on Information, computer and communications security
          March 2007
          323 pages
          ISBN:1595935746
          DOI:10.1145/1229285

          Copyright © 2007 ACM

          Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

          Publisher

          Association for Computing Machinery

          New York, NY, United States

          Publication History

          • Published: 20 March 2007

          Permissions

          Request permissions about this article.

          Request Permissions

          Check for updates

          Qualifiers

          • Article

          Acceptance Rates

          ASIACCS '07 Paper Acceptance Rate33of180submissions,18%Overall Acceptance Rate418of2,322submissions,18%

        PDF Format

        View or Download as a PDF file.

        PDF

        eReader

        View online with eReader.

        eReader