Method and system for resisting return programming-oriented attack based on zero-delay dynamic depth RAS
By implementing dynamic management of return addresses in the hardware system between the reordering buffer and memory, the problem that existing software methods are easily bypassed is solved, and effective defense against ROP attacks is achieved.
Patent Information
- Application Number
- CN202510522080.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-04-24
AI Technical Summary
Existing software methods to resist ROP attacks are easily bypassed, resulting in defense failure.
By setting a global control unit, a return address comparison unit and a zero-delay dynamic deep return address stack between the reorder buffer and memory, the hardware is used to implement stack pressing, stacking and comparison of the return address, determining whether there is a risk of return programming attacks, and sending exception processing requests to the operating system.
Effectively resist ROP attacks, prevent attackers from bypassing the protection set by software, thereby improving security and achieving attack defense without degrading processor performance.
Smart Images

Figure CN120046148A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer technology, and particularly relates to a method and system for resisting return-oriented programming attacks based on zero-latency dynamic depth RAS. Background Art
[0002] In today's digital age, software security has become the focus of attention for enterprises and individual users. With the continuous evolution of network attack methods, an attack method called Return-Oriented Programming (ROP) has gradually become the focus of the industry. ROP attacks manipulate the normal control flow of a program skillfully, enabling attackers to execute code segments pre-existing in the target program without writing any malicious code. ROP attacks are an advanced memory attack technique where attackers can execute code in the presence of security defenses. It usually forces a buffer overflow to overwrite the return address in the program stack, causing the program execution flow to jump to a carefully constructed ROP chain. The core principle of ROP attacks is to utilize existing instruction sequences in the program. Attackers carefully select and execute these execution sequences to achieve specific functions, such as executing scripts and elevating privileges. Since ROP attacks use the program's own code, they can bypass certain security mechanisms.
[0003] Most existing methods for resisting ROP attacks are implemented at the software level. Common processing methods include data execution protection, address space layout randomization, and control flow integrity, etc. The data execution protection method prevents the execution of malicious code by marking certain areas in memory as non-executable. Since this method does not allow code to be executed in the prohibited data segment, it can effectively prevent buffer overflow attacks. However, attackers can still bypass data execution protection by exploiting memory areas outside the non-execution protection segment. The address space layout randomization method randomizes the layout of code and data in memory each time the program starts to increase the difficulty for attackers to predict addresses. But attackers can still leak memory layout information through some means and thus bypass the defense of address space layout randomization. Control flow integrity aims to prevent attackers from changing the normal execution flow of a program through control flow hijacking attacks. By analyzing the control flow graph of the program, it ensures that the control flow of the program conforms to its original control flow graph. During operation, it checks whether the target of an indirect transfer instruction is in the whitelist, or checks whether the identifiers at the software function entry and call return are consistent with the expectations to determine whether the software has been tampered with and thus resist ROP attacks. However, the control flow integrity method is very complex to implement, and it is difficult to balance performance and security. Moreover, the control flow integrity method still has the possibility of being bypassed and thus becoming ineffective.
[0004] In summary, since most of the existing methods for resisting ROP attacks are implemented using software technologies, attackers may bypass the protection set by the software, resulting in the failure of ROP attack resistance. Summary of the Invention
[0005] In view of this, the present invention proposes a method and system for resisting return-oriented programming attacks based on zero-latency dynamic depth RAS, which effectively resists ROP attacks through hardware to solve the technical problem that the existing software methods for resisting ROP attacks are prone to failure.
[0006] In a first aspect, the present invention provides a method for resisting return-oriented programming attacks based on zero-latency dynamic depth RAS. The method for resisting return-oriented programming attacks based on zero-latency dynamic depth RAS includes the following steps: Send a control signal according to the type of the instruction to be committed at the current cycle in the reorder buffer; When the type of the instruction to be committed at the current cycle is a call instruction, perform a stack push operation on the return address included in the instruction to be committed in the reorder buffer according to the control signal; When the type of the instruction to be committed at the current cycle is a return instruction, perform a stack pop operation according to the control signal, provide the popped return address, and compare the provided popped return address with the return address included in the instruction to be committed at the current cycle in the reorder buffer according to the control signal; If the provided popped return address is inconsistent with the return address included in the instruction to be committed at the current cycle in the reorder buffer, it indicates that the return address has been modified, generate an exception handling request signal, notify the reorder buffer that the instruction to be committed at the current cycle has a risk of return-oriented programming attack, and send an exception handling request to the operating system to process the instruction; if the provided popped return address is consistent with the return address included in the instruction to be committed at the current cycle in the reorder buffer, it indicates that the return address has not been modified, the instruction to be committed at the current cycle has no risk of return-oriented programming attack, and control the reorder buffer to commit the instruction at the current cycle.
[0007] Further, in the above method for resisting return-oriented programming attacks based on zero-latency dynamic-depth RAS, the method further includes a step of dynamically adjusting the depth of the return address stack. The step of dynamically adjusting the depth of the return address stack includes: after each push or pop operation is executed, according to the amount of data in the current return address stack and the transmission behavior threshold, read the return addresses in the reorder buffer from the memory in order and write them to the bottom of the return address stack, or deposit the return addresses in the reorder buffer saved in the return address stack into the memory in order starting from the bottom of the return address stack. Among them, if the amount of data in the return address stack reaches twice the transmission behavior threshold, deposit the return address data between the bottom address of the return address stack and the address of the transmission behavior threshold into the memory in order. If the amount of data in the return address stack does not reach the transmission behavior threshold, take out the number of return addresses equal to the transmission behavior threshold from the memory in order and deposit them between the bottom address of the return address stack and the specified address, where the specified address is the difference between the bottom address and the address of the transmission behavior threshold.
[0008] Further, in the above method for resisting return-oriented programming attacks based on zero-latency dynamic-depth RAS, the step of dynamically adjusting the depth of the return address stack includes: After each push or pop operation is executed, first calculate the difference between the top pointer and the bottom pointer of the return address stack to obtain the amount of data in the current return address stack; If the difference is equal to twice the transmission behavior threshold, deposit the return address data between the bottom pointer and the address obtained by adding the transmission behavior threshold to the bottom pointer into the memory in order, and set the value of the bottom pointer to the sum of the value of the bottom pointer and the transmission behavior threshold; If the difference is less than the transmission behavior threshold, take out the number of return address data equal to the transmission behavior threshold from the memory in order and deposit them into the return address stack from the bottom pointer to the address obtained by subtracting the transmission behavior threshold from the bottom pointer, and set the value of the bottom pointer to the difference between the value of the bottom pointer and the transmission behavior threshold.
[0009] Further, in the above method for resisting return-oriented programming attacks based on zero-latency dynamic-depth RAS, the control signal is provided with 3 flag bits: a validity flag bit, a call flag bit, and a return flag bit; If there is a call instruction among the instructions to be committed at the current cycle in the reorder buffer, determine that the type of the instruction to be committed at the current cycle is a call instruction, set the validity flag bit and the call flag bit of the issued control signal to be valid, perform a push operation after receiving the control signal, and read the return address included in the instruction to be committed at the current cycle from the reorder buffer entry and write it to the top of the return address stack; If there is a return instruction among the instructions to be committed in the current cycle in the reorder buffer, it is determined that the type of the instruction to be committed in the current cycle is a return instruction, and the validity flag bit and the return flag bit of the issued control signal are set to valid. After receiving the control signal, a stack pop operation is performed, the return address is read from the top of the return address stack, and compared with the return address in the reorder buffer entry; If the two return addresses from the reorder buffer entry and the return address stack entry are inconsistent, an exception handling request signal is generated, notifying the reorder buffer that there is a risk of return-oriented programming attack for the instruction to be committed in the current cycle, and sending an exception handling request to the operating system to process the instruction.
[0010] In a second aspect, the present invention further provides a system for resisting return-oriented programming attacks based on zero-latency dynamic-depth RAS. The system is arranged between the reorder buffer and the memory and interacts with the reorder buffer and the memory, and includes: a global control unit, a return address comparison unit, and a zero-latency dynamic-depth return address stack, where: The global control unit issues a control signal according to the type of the instruction to be committed in the current cycle in the reorder buffer; When the type of the instruction to be committed in the current cycle is a call instruction, the zero-latency dynamic-depth return address stack performs a push operation on the return address included in the instruction to be committed in the reorder buffer according to the control signal; when the type of the instruction to be committed in the current cycle is a return instruction, the zero-latency dynamic-depth return address stack performs a pop operation according to the control signal, and provides the popped return address to the return address comparison unit; When the type of the instruction to be committed in the current cycle is a return instruction, the return address comparison unit compares the popped return address provided by the zero-latency dynamic-depth return address stack with the return address included in the instruction to be committed in the reorder buffer according to the control signal. If the popped return address provided by the zero-latency dynamic-depth return address stack is inconsistent with the return address included in the instruction to be committed in the reorder buffer, the return address comparison unit generates an exception handling request signal, notifying the reorder buffer and the global control unit that there is a risk of return-oriented programming attack for the instruction to be committed in the current cycle, and the global control unit sends an exception handling request to the operating system to process the instruction.
[0011] Further, in the above system for resisting return-oriented programming attacks based on zero-latency dynamic-depth RAS, the zero-latency dynamic-depth return address stack includes: A return address stack for storing the return addresses in the reorder buffer; A transmission control subunit, configured to control data transmission between the return address stack and the memory, read the return addresses in the reorder buffer from the memory in sequence according to the current amount of data in the stack and write them to the bottom of the stack, or deposit the return addresses in the reorder buffer saved in the stack into the memory from the bottom of the stack in sequence; A data channel, configured to transmit data between the return address stack and the memory; A threshold register, configured to configure a transmission behavior threshold of the transmission control subunit, where the transmission behavior threshold is used to measure whether address data is transmitted between the return address stack and the memory.
[0012] Further, in the above system for resisting return-oriented programming attacks based on zero-latency dynamic-depth RAS, the global control unit includes a type-checking subunit and a control subunit. Among them, the type-checking subunit obtains the opcode of the instruction to be committed in the current cycle from the reorder buffer, determines the type of the instruction to be committed in the current cycle, and notifies the control subunit to issue a corresponding control signal. The control subunit issues a control signal and controls the behaviors of the zero-latency dynamic-depth return address stack and the return address comparison unit.
[0013] Further, in the above system for resisting return-oriented programming attacks based on zero-latency dynamic-depth RAS, the return address comparison unit includes: An address comparison subunit, which obtains return addresses from the reorder buffer and the zero-latency dynamic-depth return address stack and performs a comparison operation; A notification subunit, which receives a comparison result from the address comparison subunit, determines whether to notify the global control unit to send an exception handling request to the operating system, and controls whether to commit the instruction in the current cycle in the reorder buffer.
[0014] Further, in the above system for resisting return-oriented programming attacks based on zero-latency dynamic-depth RAS, the control signal is provided with 3 flag bits: a validity flag bit, a call flag bit, and a return flag bit; If there is a call instruction among the instructions to be committed in the current cycle in the reorder buffer, it is determined that the type of the instruction to be committed in the current cycle is a call instruction, and the control subunit is notified to issue a corresponding control signal. The validity flag bit and the call flag bit of the control signal issued by the control subunit are set to valid and passed to the zero-latency dynamic-depth return address stack and the return address comparison unit. After receiving the control signal, the zero-latency dynamic-depth return address stack performs a push operation, reads the return address included in the instruction to be committed in the current cycle from the reorder buffer entry, and writes it to the top of the return address stack of the zero-latency dynamic-depth return address stack; If there is a return instruction among the instructions to be committed in the current cycle in the reorder buffer, it is determined that the type of the instruction to be committed in the current cycle is a return instruction, and the control subunit is notified to issue a corresponding control signal. The validity flag bit and the return flag bit of the control signal issued by the control subunit are set to valid and passed to the zero-latency dynamic-depth return address stack and the return address comparison unit. After receiving the control signal, the zero-latency dynamic-depth return address stack performs a pop operation. After receiving the control signal, the return address comparison unit reads the return address from the top of the return address stack of the zero-latency dynamic-depth return address stack and compares it with the return address in the reorder buffer entry; If the two return addresses from the reorder buffer entry and the return address stack entry are inconsistent, the notification subunit generates an exception handling request signal and notifies the reorder buffer and the global control unit that the instruction to be committed in the current cycle has a risk of return-oriented programming attack. The global control unit sends an exception handling request to the operating system to process the instruction.
[0015] The method and system for resisting return-oriented programming attacks based on zero-latency dynamic-depth RAS of the present invention have the following advantages and beneficial effects: The present invention adds a system including a global control unit, a return address comparison unit, and a zero-latency dynamic-depth return address stack between the reorder buffer and the memory. The global control unit identifies the type of the instruction to be committed in the current cycle and controls the behaviors of the zero-latency dynamic-depth return address stack and the return address comparison unit. When the instruction is a call instruction, the zero-latency dynamic-depth return address stack pushes the return address in the instruction onto the stack. When the instruction is a return instruction, the zero-latency dynamic-depth return address stack pops the return address saved at the top of the stack. The return address comparison unit compares whether the return address data saved at the top of the stack is consistent with the return address of the instruction to be committed in the current cycle in the reorder buffer, so as to determine whether the return address of the call instruction has been tampered with, and thus determine whether there is a risk of return-oriented programming attack for the instruction to be committed in the current cycle. When there is a risk of return-oriented programming attack, the global control unit sends an exception handling request to the operating system to process the instruction. When there is no risk of return-oriented programming attack, the global control unit controls the reorder buffer to commit the instruction in the current cycle.
[0016] The present invention abandons the method of using software technology to implement the defense against return-oriented programming attacks in the prior art, and solves the problem that attackers may bypass the protection set by software, resulting in the failure of the defense against return-oriented programming attacks. In the method and system for defending against return-oriented programming attacks based on zero-latency dynamic depth RAS of the present invention, the behaviors of the zero-latency dynamic depth return address stack and the return address comparison unit are controlled by the global control unit. Operations such as return address push and pop operations and return address comparison do not require the participation of the processor, thereby realizing effective defense against return-oriented programming attacks in a hardware manner without reducing the performance of the processor. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The drawings described herein are used to provide a further understanding of the embodiments of the present invention, and constitute a part of the present invention. The illustrative embodiments and descriptions thereof of the present invention are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings: Figure 1 It is a flowchart of a method for defending against return-oriented programming attacks based on zero-latency dynamic depth RAS provided by an embodiment of the present invention; Figure 2 It is a schematic flowchart of the dynamic depth adjustment step of the return address stack in a method for defending against return-oriented programming attacks based on zero-latency dynamic depth RAS provided by an embodiment of the present invention; Figure 3 It is a block diagram of a system for defending against return-oriented programming attacks based on zero-latency dynamic depth RAS provided by an embodiment of the present invention; Figure 4 It is a schematic diagram of the overall structure of a system for defending against return-oriented programming attacks based on zero-latency dynamic depth RAS provided by an embodiment of the present invention; Figure 5 It is a specific implementation block diagram of a system for defending against return-oriented programming attacks based on zero-latency dynamic depth RAS provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] The following are embodiments in conjunction with the drawings to further illustrate the technical solutions provided by the present invention. It should be understood that the system structure and business scenarios provided in the embodiments of the present invention are mainly for explaining possible implementation manners of the technical solutions of the present invention, and should not be construed as the only limitation of the technical solutions of the present invention. Those skilled in the art know that with the evolution of the system structure and the emergence of new business scenarios, the technical solutions provided by the present invention are equally applicable to similar technical problems.
[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which this invention belongs. In case of any inconsistency, the meaning stated in this specification or the meaning derived from the content recorded in this specification shall prevail. Additionally, the terms used herein are for the purpose of describing embodiments of the present invention only and are not intended to limit the present invention.
[0020] Figure 1 The flowchart shows a method for resisting return-oriented programming attacks based on zero-latency dynamic depth RAS provided by an embodiment of the present invention. As Figure 1 shown, the method for resisting return-oriented programming attacks based on zero-latency dynamic depth RAS includes the following steps: Step S1: Send a control signal according to the type of the instruction to be committed at the current cycle in the reorder buffer.
[0021] In an embodiment of the present invention, the reorder buffer (ROB) stores the instruction sequence to be executed, including all information of each instruction submission, such as index, opcode, and return address data.
[0022] At the beginning of each cycle, access the opcode of the instruction to be committed at the current cycle in the reorder buffer, determine whether the type of the instruction to be committed at the current cycle is a call instruction or a ret instruction according to the opcode, and send a control signal according to the instruction type, so as to perform different behaviors according to the control signal.
[0023] Step S2: When the type of the instruction to be committed at the current cycle is a call instruction, perform a push operation on the return address included in the instruction to be committed in the reorder buffer according to the control signal.
[0024] Step S3: When the type of the instruction to be committed at the current cycle is a ret instruction, perform a pop operation according to the control signal, provide the popped return address, and compare the provided popped return address with the return address included in the instruction to be committed at the current cycle in the reorder buffer according to the control signal.
[0025] Step S4: If the provided popped return address is inconsistent with the return address included in the instruction to be committed at the current cycle in the reorder buffer, it indicates that the return address has been modified, generate an exception handling request signal, notify the reorder buffer that the instruction to be committed at the current cycle has a risk of return-oriented programming attack, and send an exception handling request to the operating system to process the instruction; if the provided popped return address is consistent with the return address included in the instruction to be committed at the current cycle in the reorder buffer, it indicates that the return address has not been modified, the instruction to be committed at the current cycle has no risk of return-oriented programming attack, and control the reorder buffer to commit the instruction at the current cycle.
[0026] In an embodiment of the present invention, RAS represents the Return Address Stack.
[0027] Further, to expand the size of the zero-latency dynamic depth return address stack space and reduce the consumption of hardware resources, a method for resisting return-oriented programming attacks based on zero-latency dynamic depth RAS provided by an embodiment of the present invention further includes a step of dynamically adjusting the depth of the return address stack. Specifically, the step of dynamically adjusting the depth of the return address stack includes: after each push or pop operation is executed, according to the amount of data in the current return address stack and the transmission behavior threshold, read the return addresses in the reorder buffer from the memory in sequence and write them to the bottom of the return address stack, or deposit the return addresses in the reorder buffer saved in the return address stack into the memory in sequence starting from the bottom of the return address stack.
[0028] Specifically, after each push or pop operation is executed, if the amount of data in the return address stack is large, for example, when it reaches twice the transmission behavior threshold, the return address data between the bottom address of the return address stack and the transmission behavior threshold address is deposited into the memory in sequence, and the bottom address is modified. That is to say, some address segments in the memory are used to store the data that is not temporarily used in the return address stack, and these data are retrieved from the memory to the return address stack when needed, thereby reducing the consumption of hardware resources. When the amount of data in the return address stack does not reach the transmission behavior threshold, retrieve the number of return addresses equal to the transmission behavior threshold from the memory in sequence and deposit them between the bottom address of the return address stack and the specified address, where the specified address is the difference between the bottom address and the transmission behavior threshold address. Thus, by reading the return address data from the memory into the stack when the stack table entries are insufficient, the space of the return address stack is expanded, that is, the memory supports the depth expansion when the stack table entries are insufficient through the data channel. Therefore, a method for resisting return-oriented programming attacks based on zero-latency dynamic depth RAS provided by an embodiment of the present invention can realize the dynamic depth adjustment of the return address stack, and thus can complete the resistance to return-oriented programming attacks in the case of ultra-deep function calls.
[0029] In an embodiment of the present invention, the transmission behavior threshold is configured by the user. Preferably, the transmission behavior threshold is configured to be less than half of the number of return address stack entries.
[0030] Figure 2 For the flow chart of the step of dynamically adjusting the depth of the return address stack in a method for resisting return-oriented programming attacks based on zero-latency dynamic depth RAS provided by an embodiment of the present invention, as Figure 2 shown, the specific implementation process of dynamically adjusting the depth of the return address stack is as follows: After each push or pop operation is executed, first calculate the difference between the top pointer and the bottom pointer of the return address stack, that is, the stack capacity; If the difference is equal to twice the transmission behavior threshold, that is, when the amount of data in the return address stack reaches twice the transmission behavior threshold, the return address data between the stack bottom pointer and the address obtained by adding the transmission behavior threshold to the stack bottom pointer, that is, the return address data between the stack bottom address of the return address stack and the address of the transmission behavior threshold, is stored in the memory in order, and the value of the stack bottom pointer is set to the sum of the value of the stack bottom pointer and the transmission behavior threshold, that is, stack bottom pointer = stack bottom pointer + transmission behavior threshold. Part of the address segment in the memory stores the data in the return address stack that is not temporarily used; If the difference is less than the transmission behavior threshold, that is, when the amount of data in the return address stack does not reach the transmission behavior threshold, the number of return address data equal to the transmission behavior threshold is taken out from the memory in order and stored in the address from the stack bottom pointer of the return address stack to the address obtained by subtracting the transmission behavior threshold from the stack bottom pointer, and the value of the stack bottom pointer is set to the difference between the value of the stack bottom pointer and the transmission behavior threshold, that is, stack bottom pointer = stack bottom pointer - transmission behavior threshold.
[0031] Among them, in the embodiment of the present invention, in the above-mentioned dynamic depth adjustment step of the return address stack, if a default occurs when comparing the difference with the transmission behavior threshold, the operation ends.
[0032] Further, in the embodiment of the present invention, the control signal is provided with 3 flag bits: a validity flag bit (valid), a call flag bit (isCall), and a return flag bit (isRet); when the validity flag bit signal is 1, it indicates that the signal transmitted this time is valid; when the call flag bit signal is 1, it indicates that this operation is a call instruction; when the return flag bit signal is 1, it indicates that this operation is a return instruction.
[0033] If there is a call instruction in the instructions to be committed in the current cycle in the reorder buffer, it is determined that the type of the instruction to be committed in the current cycle is a call instruction, the validity flag bit and the call flag bit of the issued control signal are set to valid (set to 1), and after receiving the control signal, a push operation is performed, and the return address included in the instruction to be committed in the current cycle is read out from the reorder buffer entry and written to the top of the return address stack; If there is a return instruction in the instructions to be committed in the current cycle in the reorder buffer, it is determined that the type of the instruction to be committed in the current cycle is a return instruction, the validity flag bit and the return flag bit of the issued control signal are set to valid (set to 1), and after receiving the control signal, a pop operation is performed, the return address is read out from the top of the return address stack, and compared with the return address in the reorder buffer entry; If the two return addresses from the reorder buffer entry and the return address stack entry are inconsistent, an exception handling request signal is generated, notifying the reorder buffer that the instruction to be committed in the current cycle has a risk of return-oriented programming attack, and sending an exception handling request to the operating system to process the instruction.
[0034] Such asFigures 3 - 5 As shown in Figures 3 - 5 , to implement the above method for defending against return-oriented programming attacks based on zero-latency dynamic depth RAS provided by the embodiments of the present invention, the embodiments of the present invention provide a system for defending against return-oriented programming attacks based on zero-latency dynamic depth RAS. This system is set between the re-order buffer (ROB) and the memory and interacts with the re-order buffer and the memory. It includes a global control unit 101, a return address comparison unit 103, and a zero-latency dynamic depth return address stack 102. The global control unit 101 issues a control signal according to the type of the instruction to be committed at the current cycle in the re-order buffer. When the type of the instruction to be committed at the current cycle is a call instruction, the zero-latency dynamic depth return address stack 102 performs a push operation on the return address included in the instruction to be committed in the re-order buffer according to the control signal. When the type of the instruction to be committed at the current cycle is a return instruction, the zero-latency dynamic depth return address stack 102 performs a pop operation according to the control signal and provides the popped return address to the return address comparison unit 103. When the type of the instruction to be committed at the current cycle is a return instruction, the return address comparison unit 103 compares the popped return address provided by the zero-latency dynamic depth return address stack 102 with the return address included in the instruction to be committed at the current cycle in the re-order buffer according to the control signal. If the popped return address provided by the zero-latency dynamic depth return address stack 102 is inconsistent with the return address included in the instruction to be committed at the current cycle in the re-order buffer, the return address comparison unit 103 generates an exception handling request signal and notifies the re-order buffer and the global control unit 101 that the instruction to be committed at the current cycle has a risk of return-oriented programming attack. The global control unit 101 sends an exception handling request to the operating system to process the instruction.
[0035] Reference Figure 5 , in the embodiments of the present invention, the re-order buffer stores an instruction sequence to be executed, including all information for each instruction submission, such as an index, an opcode, and return address data. The global control unit 101 includes a type check sub-unit and a control sub-unit. The type check sub-unit obtains the opcode of the instruction to be committed at the current cycle from the re-order buffer, determines the type of the instruction to be committed at the current cycle, and notifies the control sub-unit to issue a corresponding control signal. The control sub-unit issues a control signal and controls the behaviors of the zero-latency dynamic depth return address stack 102 and the return address comparison unit 103. Both use the same control signal, and the control signal has 3 flag bits: a validity flag bit, a call flag bit, and a return flag bit. When the validity flag bit signal is 1, it indicates that the signal transmitted this time is valid. When the call flag bit signal is 1, it indicates that this operation is a call instruction. When the return flag bit signal is 1, it indicates that this operation is a return instruction.
[0036] Specifically, at the beginning of each cycle, the type check subunit in the global control unit 101 accesses the opcode bit in the reorder buffer entry. If it is found that there is a call instruction among the instructions to be committed in the current cycle, the validity flag bit and the call flag bit of the control signal are set to valid (set to 1), and the return flag bit is set to invalid (set to 0), and then passed to the zero-latency dynamic depth return address stack 102 and the return address comparison unit 103. After receiving the control signal, the zero-latency dynamic depth return address stack 102 performs a push operation, reads the corresponding return address from the reorder buffer entry, and writes it to the top of the return address stack of the zero-latency dynamic depth return address stack 102. If it is found that there is a return instruction among the instructions to be committed in the current cycle, the validity flag bit and the return flag bit of the control signal are set to valid (set to 1), and the call flag bit is set to invalid (set to 0), and then passed to the zero-latency dynamic depth return address stack 102 and the return address comparison unit 103. After receiving the control signal, the zero-latency dynamic depth return address stack 102 performs a pop operation, and after receiving the control signal, the return address comparison unit 103 reads the return address from the top of the return address stack of the zero-latency dynamic depth return address stack 102 and compares it with the return address in the reorder buffer entry. If it is found that there is no call or return instruction among the instructions to be committed in the current cycle, the validity flag bit signal is set to 0, and no other unit performs any action.
[0037] Reference Figure 5, the zero-latency dynamic-depth return address stack 102 interacts with the reorder buffer and the return address comparison unit 103 according to the control signals transmitted by the global control unit 101. The zero-latency dynamic-depth return address stack 102 includes a return address stack, a transmission control subunit, a threshold register, and a data channel; the return address stack is a stack with N entries, where N can be 32, and it has a stack top pointer and a stack bottom pointer. The stack top pointer represents the address of the current stack top, and the stack bottom pointer represents the address of the current stack bottom. The return address stack stores the return addresses in the reorder buffer through the threshold register, that is, each entry in the return address stack stores the return address after each call instruction is committed, and provides the return address for the return address comparison unit 103 when it works; the transmission control subunit is used to control the data transmission between the return address stack and the memory. Specifically, it reads the return addresses in the reorder buffer from the memory in sequence according to the current data volume in the return address stack and writes them to the bottom of the return address stack, or deposits the return addresses in the reorder buffer saved in the return address stack from the bottom of the return address stack into the memory in sequence; the data channel is used to transmit data between the return address stack and the memory; the threshold register is used to configure the transmission behavior threshold of the transmission control subunit, and the transmission behavior threshold is used to measure whether address data is transmitted between the return address stack and the memory; the transmission behavior threshold is configured by the user through the threshold register. Preferably, the transmission behavior threshold is configured by the threshold register to be less than half of the number of entries N in the return address stack (i.e., transmission behavior threshold < N / 2).
[0038] When the processor executes a function call instruction (call instruction), the zero-latency dynamic-depth return address stack 102 performs a push operation to push the return address of the call instruction onto the stack top; when the processor executes a function return instruction (ret instruction), the zero-latency dynamic-depth return address stack 102 performs a pop operation to pop the return address from the stack top, and the program will return to this address to continue execution. Since function calls and returns usually occur in pairs, and the return address is determined at the time of the call, therefore, the characteristics of the zero-latency dynamic-depth return address stack 102 can be used to determine whether the return address of the call instruction has been modified, so as to resist return-oriented programming attacks.
[0039] Preferably, each time the reorder buffer performs the commit operation of a call instruction, the validity flag bit and the call flag bit of the control signal received by the zero-latency dynamic depth return address stack 102 from the global control unit 101 are 1. The return address of this call instruction is written into the entry corresponding to the top-of-stack pointer address, and the top-of-stack pointer is incremented by one. Each time the reorder buffer performs the commit operation of a return instruction, the validity flag bit and the return flag bit of the control signal received by the zero-latency dynamic depth return address stack 102 from the global control unit 101 are 1. The content in the entry corresponding to the top-of-stack pointer address is read out and sent to the return address comparison unit 103, and the top-of-stack pointer is decremented by one.
[0040] The return address comparison unit 103 includes an address comparison subunit and a notification subunit; the address comparison subunit obtains the return addresses from the reorder buffer and the zero-latency dynamic depth return address stack 102 and performs a comparison operation, and passes the comparison result to the notification subunit. That is, when the return address comparison unit 103 receives the control signal sent by the global control unit 101, the address comparison subunit performs a comparison operation on the two return addresses from the reorder buffer entry and the return address stack entry; the notification subunit determines whether to notify the global control unit 101 to send an exception handling request to the operating system and controls whether the reorder buffer commits the current instruction according to the result transmitted by the address comparison subunit. Specifically, if the two return addresses from the reorder buffer entry and the return address stack entry are the same, the notification subunit notifies the reorder buffer and the global control unit 101 that the current committed return instruction is risk-free; if the two return addresses from the reorder buffer entry and the return address stack entry are different, it indicates that the return address has been modified. The notification subunit generates an exception handling request signal, such as an exception signal, and notifies the reorder buffer and the global control unit 101 that the current instruction commit is risky. The global control unit 101 sends an exception handling request to the operating system to process this instruction.
[0041] Further, in an optional implementation manner of the embodiment of the present invention, the zero-latency dynamic depth return address stack 102 further includes a pointer calculation module, which is used to calculate the size of the data in the stack according to the top-of-stack pointer and the bottom-of-stack address, calculate the pointer address read from the memory into the stack and the pointer address read from the stack into the memory during the data transmission process between the return address stack and the memory, so as to realize the address data interaction between the return address stack and the memory.
[0042] In summary, the present invention adds a system including a global control unit 101, a return address comparison unit 103, and a zero-latency dynamic depth return address stack 102 between the reorder buffer and the memory. The global control unit 101 identifies the type of the instruction to be committed in the current cycle and controls the behaviors of the zero-latency dynamic depth return address stack 102 and the return address comparison unit 103. When the instruction is a call instruction, the zero-latency dynamic depth return address stack 102 pushes the return address in the instruction onto the stack. When the instruction is a return instruction, the zero-latency dynamic depth return address stack 102 pops the return address saved at the top of the stack. The return address comparison unit 103 compares whether the return address data saved at the top of the stack is consistent with the return address of the instruction to be committed in the current cycle in the reorder buffer, so as to determine whether the return address of the call instruction is tampered with, thereby determining whether there is a risk of return-oriented programming attack for the instruction to be committed in the current cycle. And when there is a risk of return-oriented programming attack, the global control unit 101 sends an exception handling request to the operating system to process the instruction. When there is no risk of return-oriented programming attack, the global control unit 101 controls the reorder buffer to commit the instruction in the current cycle.
[0043] The present invention abandons the method of using software technology to resist return-oriented programming attacks in the prior art, and solves the problem that attackers may bypass the protection set by software, resulting in the failure of resistance to return-oriented programming attacks. In the method and system for resisting return-oriented programming attacks based on zero-latency dynamic depth RAS of the present invention, the behaviors of the zero-latency dynamic depth return address stack 102 and the return address comparison unit 103 are controlled by the global control unit 101. Operations such as return address pushing and popping, and return address comparison do not require the participation of the processor, so as to effectively resist return-oriented programming attacks in a hardware manner without reducing the performance of the processor.
[0044] It should be noted that the embodiments described in the present invention are only a part of the embodiments of the present invention, rather than all the embodiments. The components of the embodiments of the present invention described and illustrated in the drawings can be arranged and designed in various different configurations. Therefore, the detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but only represents the selected embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0045] The terms "first," "second," "third," etc. or similar terms such as Module A, Module B, Module C, etc. in the specification and claims are only used to distinguish similar objects and do not represent a specific order for the objects. Understandably, the specific order or sequence can be interchanged when permitted so that the embodiments of the present invention described herein can be implemented in an order other than that illustrated or described herein.
[0046] In the above description, the reference numerals representing steps do not necessarily mean that the steps will be executed in this order. It may also include intermediate steps or be replaced by other steps. The order of the front and rear steps can be interchanged when permitted, or they can be executed simultaneously.
[0047] The term "comprising" used in the specification and claims should not be construed as being limited to the content listed thereafter; it does not exclude other elements or steps. Therefore, it should be interpreted as specifying the existence of the mentioned features, wholes, steps, or components, but does not exclude the existence or addition of one or more other features, wholes, steps, or components and their groups. Therefore, the expression "a device comprising device A and B" should not be limited to a device consisting only of components A and B.
[0048] The "one embodiment" or "embodiment" mentioned in this specification means that the specific features, structures, or characteristics described in connection with the embodiment are included in at least one embodiment of the present invention. Therefore, the phrases "in one embodiment" or "in an embodiment" that appear throughout this specification do not necessarily all refer to the same embodiment, but may refer to the same embodiment. In addition, in various embodiments of the present invention, if there is no special explanation and logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced to each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0049] Note that the above is only the preferred embodiment of the present invention and the technical principles applied. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of the present invention. Therefore, although the present invention has been described in more detail through the above embodiments, the present invention is not limited to the above embodiments. Without departing from the concept of the present invention, it can also include more other equivalent embodiments, all of which fall within the protection scope of the present invention.
Claims
1. A method for defending against return-oriented programming attacks based on zero-delay dynamic deep RAS, characterized in that: The method for resisting return-oriented programming attacks based on zero-delay dynamic deep RAS comprises the following steps: Sending a control signal according to the type of the instruction to be submitted in the reorder buffer; When the type of the instruction to be submitted is a call instruction, a stacking operation is performed on the return address included in the instruction to be submitted in the reordering buffer according to the control signal; When the type of the instruction to be submitted is a return instruction, a pop operation is performed according to a control signal, and a pop return address is provided, and the provided pop return address is compared with the return address included in the instruction to be submitted in the reorder buffer according to the control signal; If the provided pop return address is inconsistent with the return address included in the current instruction to be submitted in the reorder buffer, it indicates that the return address has been modified, and an exception handling request signal is generated to notify the reorder buffer that the current instruction to be submitted has a risk of return-oriented programming attack, and send an exception handling request to the operating system to process the instruction; if the provided pop return address is consistent with the return address included in the current instruction to be submitted in the reorder buffer, it indicates that the return address has not been modified, and the current instruction to be submitted does not have a risk of return-oriented programming attack, and the reorder buffer is controlled to submit the current instruction.
2. The method for defending against return-oriented programming attacks based on zero-delay dynamic deep RAS according to claim 1, characterized in that: The method also includes a step of dynamically adjusting the depth of the return address stack, which includes: after each push or pop operation is performed, according to the current data volume in the return address stack and the transmission behavior threshold, the return addresses in the reorder buffer are sequentially read from the memory and written to the bottom of the return address stack, or the return addresses in the reorder buffer stored in the return address stack are sequentially stored in the memory starting from the bottom of the return address stack, wherein if the data volume in the return address stack reaches twice the transmission behavior threshold, the return address data between the bottom address of the return address stack and the transmission behavior threshold address are sequentially stored in the memory, and if the data volume in the return address stack does not reach the transmission behavior threshold, the return addresses equal to the transmission behavior threshold are sequentially taken out from the memory and stored between the bottom address of the return address stack and a specified address, wherein the specified address is the difference between the bottom address and the transmission behavior threshold address.
3. The method for resisting return-oriented programming attacks based on zero-delay dynamic deep RAS according to claim 2, characterized in that: The step of dynamically adjusting the depth of the return address stack includes: After each push or pop operation, the difference between the top pointer and the bottom pointer of the return address stack is calculated to obtain the amount of data in the current return address stack. If the difference is equal to twice the transmission behavior threshold, the return address data between the stack bottom pointer and the address of the stack bottom pointer plus the transmission behavior threshold are sequentially stored in the memory, and the value of the stack bottom pointer is set to the sum of the value of the stack bottom pointer and the transmission behavior threshold; If the difference is less than the transmission behavior threshold, the return address data of the number equal to the transmission behavior threshold are taken out from the memory in sequence and stored in the stack bottom pointer of the return address stack to the address of the stack bottom pointer minus the transmission behavior threshold, and the value of the stack bottom pointer is set to the difference between the value of the stack bottom pointer and the transmission behavior threshold.
4. The method for defending against return-oriented programming attacks based on zero-delay dynamic deep RAS according to claim 1, characterized in that: The control signal is provided with three flags: a validity flag, a call flag and a return flag; If there is a call instruction among the instructions to be submitted in the reorder buffer, the type of the instruction to be submitted is determined to be a call instruction, the validity flag bit and the call flag bit of the control signal sent are set to be valid, and after receiving the control signal, a push operation is performed, and the return address included in the instruction to be submitted is read from the reorder buffer table entry and written to the top of the return address stack; If there is a return instruction among the instructions to be submitted in the reorder buffer, the type of the instruction to be submitted is determined to be a return instruction, the validity flag bit and the return flag bit of the control signal sent are set to be valid, and after receiving the control signal, a pop operation is performed, the return address is read from the top of the return address stack, and compared with the return address in the reorder buffer entry; If the two return addresses from the reorder buffer table entry and the return address stack table entry are inconsistent, an exception handling request signal is generated to notify the reorder buffer that the instruction to be submitted has a risk of return-oriented programming attack, and an exception handling request is sent to the operating system to process the instruction.
5. A system for defending against return-oriented programming attacks based on zero-delay dynamic deep RAS, characterized in that: The system is arranged between a reorder buffer and a memory and interacts with the reorder buffer and the memory, and includes: a global control unit, a return address comparison unit, and a zero-delay dynamic depth return address stack, wherein: The global control unit sends a control signal according to the type of the instruction to be submitted in the reorder buffer; When the type of the instruction to be submitted is a call instruction, the zero-latency dynamic depth return address stack performs a stack push operation on the return address included in the instruction to be submitted in the reorder buffer according to the control signal; when the type of the instruction to be submitted is a return instruction, the zero-latency dynamic depth return address stack performs a stack pop operation according to the control signal, and provides the popped return address to the return address comparison unit; When the type of the instruction to be submitted is a return instruction, the return address comparison unit compares the popped return address provided by the zero-latency dynamic depth return address stack with the return address included in the instruction to be submitted in the reorder buffer according to the control signal. If the popped return address provided by the zero-latency dynamic depth return address stack is inconsistent with the return address included in the instruction to be submitted in the reorder buffer, the return address comparison unit generates an exception handling request signal to notify the reorder buffer and the global control unit that the instruction to be submitted has a risk of return-oriented programming attack, and the global control unit sends an exception handling request to the operating system to process the instruction.
6. The system for defending against return-oriented programming attacks based on zero-delay dynamic deep RAS according to claim 5, characterized in that: The zero-delay dynamic depth return address stack includes: A return address stack, used to store the return addresses in the reorder buffer; a transmission control subunit, for controlling the data transmission between the return address stack and the memory, reading the return addresses in the reorder buffer from the memory in order according to the amount of data in the current stack and writing them to the bottom of the stack, or storing the return addresses in the reorder buffer stored in the stack in order from the bottom of the stack into the memory; A data channel, used for transmitting data between the return address stack and the memory; The threshold register is used to configure the transmission behavior threshold of the transmission control subunit, and the transmission behavior threshold is used to measure whether address data is transmitted between the return address stack and the memory.
7. The system for defending against return-oriented programming attacks based on zero-delay dynamic deep RAS according to claim 6, characterized in that: The global control unit includes a type checking subunit and a control subunit, wherein the type checking subunit obtains the opcode of the instruction to be submitted from the reordering buffer, determines the type of the instruction to be submitted, and notifies the control subunit to issue a corresponding control signal. The control subunit issues a control signal and controls the behavior of the zero-delay dynamic depth return address stack and the return address comparison unit.
8. The system for defending against return-oriented programming attacks based on zero-delay dynamic deep RAS according to claim 7, characterized in that: The return address comparison unit comprises: An address comparison subunit, which obtains a return address from the reorder buffer and the zero-delay dynamic depth return address stack and performs a comparison operation; The notification subunit receives the comparison result from the address comparison subunit, determines whether to notify the global control unit to send an exception handling request to the operating system, and controls whether the reorder buffer submits the current instruction.
9. The system for defending against return-oriented programming attacks based on zero-delay dynamic deep RAS according to claim 8, characterized in that: The control signal is provided with three flags: a validity flag, a call flag and a return flag; If there is a call instruction among the instructions to be submitted in the reorder buffer, it is determined that the type of the instruction to be submitted is a call instruction, and the control subunit is notified to send a corresponding control signal. The validity flag bit and the call flag bit of the control signal sent by the control subunit are set to be valid and transmitted to the zero-delay dynamic depth return address stack and the return address comparison unit. After receiving the control signal, the zero-delay dynamic depth return address stack performs a push operation, reads the return address included in the instruction to be submitted from the reorder buffer table entry, and writes it into the return address stack top of the zero-delay dynamic depth return address stack; If there is a return instruction in the current-patch to-be-committed instructions in the reorder buffer, it is determined that the type of the current-patch to-be-committed instruction is a return instruction, and the control subunit is notified to send a corresponding control signal. The validity flag bit and the return flag bit of the control signal sent by the control subunit are set to be valid and transmitted to the zero-delay dynamic depth return address stack and the return address comparison unit. After receiving the control signal, the zero-delay dynamic depth return address stack performs a pop operation. After receiving the control signal, the return address comparison unit reads a return address from the top of the return address stack of the zero-delay dynamic depth return address stack and compares it with the return address in the reorder buffer table entry. If the two return addresses derived from the reorder buffer table entry and the return address stack table entry are inconsistent, the notification subunit generates an exception handling request signal to notify the reorder buffer and the global control unit that the instruction to be submitted has a risk of return-oriented programming attack, and the global control unit sends an exception handling request to the operating system to process the instruction.
Citation Information
Patent Citations
Kernel-level code reuse type attack detection method based on QEMU
CN105260659A
ROP attack positioning and code capturing method oriented to Cisco IOS
CN113641995A
Router intrusion detection method and device, equipment and storage medium
CN117294455A
Cet mechanism-based method for protecting integrity of general-purpose memory
US20250036752A1