ROP attack detection method and device based on hardware characteristics
Through the ROP attack detection method based on hardware characteristics, using hardware event recording and LBR stack, the accuracy and performance overhead of detecting advanced ROP attacks in the prior art are solved, and efficient and low false alarm attack detection is achieved.
Patent Information
- Application Number
- CN202510369867.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2045-03-27
AI Technical Summary
Existing ROP attack detection methods are difficult to accurately detect advanced ROP attacks, especially ROP attacks with Gadget call-preceded, and have large performance overhead.
Based on the hardware characteristics, by obtaining the hardware event records of instruction data, specific indicators and thresholds are calculated to determine the suspected ROP attack cycle, and combined with the failure of return branch prediction in the recent branch record (LBR) stack, the false positive rate is reduced.
It realizes efficient detection of advanced ROP attacks, reduces false positive rates and reduces performance costs, and is suitable for multi-platform environments.
Smart Images

Figure CN120541833A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field related to information security, and in particular to a method and device for detecting ROP attacks based on hardware characteristics. Background Art
[0002] With the rapid development of information technology, information security issues have become increasingly important. Attackers are beginning to use more sophisticated attack methods to bypass existing defense mechanisms and achieve their goals. For example, attackers use existing code snippets in a program to construct code chains that can be exploited by themselves. This type of attack is called a code reuse attack. Return-Oriented Programming (ROP) is the most common type of code reuse attack. ROP attacks exploit program code snippets and link them together using the 'ret' instruction to bypass system security mechanisms, such as the Data Execution Prevention (DEP) mechanism in Windows. ROP attacks are widely used on multiple platforms (Windows, Linux, and Android).
[0003] Some existing detection methods, such as control flow integrity detection, require statically obtaining the destination addresses of possible indirect jumps and then rewriting the binary file to perform the detection. Without additional information such as source code and symbol tables, it is impossible to accurately disassemble the binary file, making it difficult to accurately obtain the destination addresses of all indirect jumps. Furthermore, the need to detect all indirect branches incurs a significant performance overhead. Furthermore, existing detection methods are not effective in detecting some advanced ROP attacks that can bypass coarse-grained control flow integrity checks, such as ROP attacks where the gadget is call-preceded. Summary of the Invention
[0004] The purpose of the present invention is to address at least one of the deficiencies of the prior art and to provide a ROP attack detection method and device based on hardware characteristics.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] Specifically, a ROP attack detection method based on hardware characteristics is proposed, including the following:
[0007] Acquire hardware event records of instruction data according to a preset sampling period T, wherein the hardware events include the number of call instructions executed in the instruction data, the number of return instructions, the total number of branch prediction failures, and the number of conditional branch prediction failures;
[0008] In any sampling period, based on its hardware event records, a first metric and a second metric are calculated, wherein the first metric is the number of return instructions minus the number of call instructions, and the second metric is the total number of branch prediction failures minus the number of conditional branch prediction failures;
[0009] If the first indicator is less than the first threshold, it is directly determined that there is no ROP attack in the sampling period. If the first indicator is not less than the first threshold, it is determined whether the second indicator is not less than the second threshold. If the second indicator is not less than the second threshold, the sampling period is marked as a suspected ROP attack period.
[0010] Obtain the number of consecutive return branch prediction failures recorded in the LBR stack in two adjacent suspected ROP attack cycles;
[0011] If the number of consecutive return branch prediction failures is greater than the third threshold, it is determined that no ROP attack exists in the two suspected ROP attack cycles; if it is not greater than the third threshold, it is determined that a ROP attack exists in the two suspected ROP attack cycles.
[0012] Furthermore, specifically, every 100 instructions, four hardware events, namely, the executed call instruction, the return instruction, the total number of branch prediction failures, and the number of conditional branch prediction failures, are recorded by creating a file descriptor through the function perf_event_open().
[0013] Further, specifically, the first threshold is 10 and the second threshold is 12.
[0014] Furthermore, the method of obtaining the number of consecutive return branch prediction failures recorded in the LBR stack in two adjacent suspected ROP attack cycles includes:
[0015] The prediction of the current return branch is identified by obtaining the 63rd bit in MSR_LASTBRANCH_n_FROM_IP in the LBR stack. When the value of this bit is 1, it indicates that the return branch prediction failed, and when the value is 0, it indicates that the return branch prediction did not fail.
[0016] Furthermore, the method further includes, for a sampling period that is not marked as a suspected ROP attack period and for which the first indicator is not less than the first threshold and the second indicator is less than the second threshold, evenly dividing the sampling period into a plurality of combination periods according to the order of sampling time, assuming that each combination period has N sampling periods, i.e., a length of NT, and recording the i-th combination period as {Cycle i 1. Cycle i 2, ..., Cycle i N}, where Cycle iN represents the second indicator value of the Nth sampling period in the i-th combination period. Based on the changes in the second indicator values of adjacent combination periods, abnormal combination periods are found, and the sampling periods in the abnormal combination periods are marked as suspected ROP attack periods.
[0017] Furthermore, specifically, finding abnormal combination periods based on changes in the second indicator values of adjacent combination periods includes:
[0018] Step 110: predefine loop variables and initialize i=1, then go to step 120;
[0019] Step 120: Obtain the i-th combined period as the i-th data set to be analyzed, and go to step 130;
[0020] Step 130: Determine whether i is equal to 1. If so, increase the value of i by 1 and go to step 120; if not, go to step 140.
[0021] Step 140: Perform change anomaly analysis based on the i-th data set to be analyzed and the i-1-th data set to be analyzed to obtain a change anomaly analysis result, and then go to step 150;
[0022] Step 150: If the abnormality analysis result of the i-th data set to be analyzed is abnormal, mark the abnormality and go to step 160 for execution; if no abnormality is found, go directly to step 160 for execution;
[0023] Step 160 , determine whether i is equal to N. If it is equal to N, output all abnormally marked data sets to be analyzed, that is, abnormal combination cycles. If it is not equal to N, increase the value of i by 1 and go to step 120 to execute.
[0024] Further, specifically, based on the i-th data set to be analyzed and the i-1-th data set to be analyzed, the abnormal change analysis results are obtained, including:
[0025] The i-1th data set to be analyzed is {Cycle i-1 1. Cycle i-1 2, ..., Cycle i-1 N}, Cycle i-1 j represents the jth element in the i-1th data set to be analyzed, and the value range of j is [1, N];
[0026] Take the i-1th data set to be analyzed {Cycle i-1 1. Cycle i-1 2, ..., Cycle i-1 Any element in N}Cycle i-1 The element number j of j is used as the horizontal axis, Cyclei-1 The value of j is used as the ordinate to obtain N data points in the two-dimensional coordinate system;
[0027] The N data points in the two-dimensional coordinate system are processed by a fitting algorithm to obtain the change representation curve of the i-1th data set to be analyzed, which is recorded as the change representation curve i-1;
[0028] The i-th data set to be analyzed is {Cycle i 1. Cycle i 2, ..., Cycle i N}, Cycle i j represents the jth element in the i-th data set to be analyzed;
[0029] Take the i-th data set to be analyzed {Cycle i 1. Cycle i 2, ..., Cycle i Any element in N}Cycle i The element number j of j is used as the horizontal axis, Cycle i The value of j is used as the y coordinate to obtain N data points located in the two-dimensional coordinate system;
[0030] Calculate the nearest distance values of these N data points to the change representation curve i-1 respectively and integrate them to obtain the nearest distance value sequence corresponding to the i-th data set to be analyzed {Cycle i zj1, Cycle i zj2, ..., Cycle i zjN}, Cycle i _zjj represents the jth element in the sequence of the closest distance values corresponding to the i-th data set to be analyzed;
[0031] Traverse {Cycle i zj1, Cycle i zj2, ..., Cycle i zjN}, count the number of elements M that exceed the fourth threshold;
[0032] It is determined whether the value of M is greater than a fifth threshold. If so, it is marked that the i-th data set to be analyzed has an abnormal change. If not, it is determined that the i-th data set to be analyzed has no abnormal change.
[0033] The present invention also proposes a device for detecting ROP attacks based on hardware characteristics, comprising the following:
[0034] A first data acquisition module is configured to acquire hardware event records of instruction data according to a preset sampling period T, wherein the hardware events include the number of call instructions executed in the instruction data, the number of return instructions executed, the total number of branch prediction failures, and the number of conditional branch prediction failures;
[0035] an indicator calculation module, configured to calculate a first indicator and a second indicator based on its hardware event records in any sampling period, wherein the first indicator is the number of return instructions minus the number of call instructions, and the second indicator is the total number of branch prediction failures minus the number of conditional branch prediction failures;
[0036] A first judgment module is configured to directly determine whether a ROP attack does not exist in the sampling period if the first indicator is less than a first threshold; if the first indicator is not less than the first threshold, determine whether the second indicator is not less than a second threshold; and if the second indicator is not less than the second threshold, mark the sampling period as a suspected ROP attack period;
[0037] The second data acquisition module is used to obtain the number of consecutive return branch prediction failures recorded in the LBR stack in two adjacent suspected ROP attack cycles;
[0038] The second judgment module is used to judge that there is no ROP attack in the two suspected ROP attack cycles if the number of consecutive return branch prediction failures is greater than a third threshold; if not, judge that there is a ROP attack in the two suspected ROP attack cycles.
[0039] The beneficial effects of the present invention are:
[0040] The present invention proposes a ROP attack detection method and device based on hardware characteristics. First, according to the characteristics of the ROP attack, some performance events related to the ROP attack are extracted, and then the values of the performance counters corresponding to these events are read, and normal programs and ROP attacks are classified and processed based on the performance events. At the same time, the present application combines the performance monitoring unit with the Last Branch Record (LBR) mechanism to reduce the false positives generated. Experimental results show that the method proposed in this application has a good detection effect. At the same time, compared with other methods, the method proposed in this application not only has a smaller performance cost, but can also detect more advanced ROP attacks that many other methods cannot detect. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The above and other features of the present disclosure will become more apparent through a detailed description of the embodiments shown in conjunction with the accompanying drawings. The same reference numerals in the drawings of the present disclosure represent the same or similar elements. Obviously, the drawings described below are only some embodiments of the present disclosure. It is possible for a person skilled in the art to derive other drawings based on these drawings without inventive effort. In the drawings:
[0042] Figure 1 FIG2 is a flowchart of a ROP attack detection method based on hardware characteristics of the present invention;
[0043] Figure 2 The figure shows the ROC curve of the ROP attack detection method based on hardware characteristics of the present invention during evaluation;
[0044] Figure 3 Shown is the recorded content of the LBR stack when the present invention is applied. DETAILED DESCRIPTION
[0045] The following will be combined with the embodiments and drawings to clearly and completely describe the concept, specific structure and technical effects of the present invention so as to fully understand the purpose, scheme and effect of the present invention. It should be noted that the embodiments and features in the embodiments of this application can be combined with each other unless there is a conflict. The same reference numerals used throughout the drawings indicate the same or similar parts.
[0046] Example 1, reference Figure 1 , the present invention proposes a ROP attack detection method based on hardware characteristics, including the following:
[0047] Step 110: Acquire hardware event records of instruction data according to a preset sampling period T, wherein the hardware events include the number of executed call instructions, the number of return instructions, the total number of branch prediction failures, and the number of conditional branch prediction failures in the instruction data;
[0048] Step 120: In any sampling period, based on the hardware event records, calculate a first indicator and a second indicator, wherein the first indicator is the number of return instructions minus the number of call instructions, and the second indicator is the total number of branch prediction failures minus the number of conditional branch prediction failures;
[0049] Step 130: If the first indicator is less than the first threshold, it is directly determined that there is no ROP attack in the sampling period. If the first indicator is not less than the first threshold, it is determined whether the second indicator is not less than the second threshold. If the second indicator is not less than the second threshold, the sampling period is marked as a suspected ROP attack period.
[0050] Step 140: Obtain the number of consecutive return branch prediction failures recorded in the LBR stack in two adjacent suspected ROP attack cycles;
[0051] Step 150: If the number of consecutive return branch prediction failures is greater than a third threshold, it is determined that no ROP attack exists in the two suspected ROP attack cycles; if it is not greater than the third threshold, it is determined that a ROP attack exists in the two suspected ROP attack cycles.
[0052] In this embodiment 1, first, according to the characteristics of ROP attacks, some performance events related to ROP attacks are extracted, and then the values of the performance counters corresponding to these events are read, and normal programs and ROP attacks are classified and processed based on the performance events. At the same time, this application combines the performance monitoring unit with the Last Branch Record (LBR) mechanism to reduce the false positives generated. The experimental results show that the method proposed in this application has a good detection effect. At the same time, compared with other methods, the method proposed in this application not only has a smaller performance cost, but can also detect more advanced ROP attacks that many other methods cannot detect.
[0053] Specifically, the processor's performance monitoring unit (PMU) records performance events related to ROP attacks. The PMU operates in two modes: counting mode and sampling mode. The present invention uses the PMU's sampling mode, which reads the value of the ROP attack-related performance event counter every certain instruction interval.
[0054] The performance counter value can be set to be read every N instructions (sampling frequency). When the value of N is 1, the performance counter value is read every time an instruction is executed. When the value of N is 1000, the performance event counter value is read every 1000 instructions. The setting of the value of N is closely related to the detection of ROP attacks. If the value of N is too large, there will be a large number of false positives in the detection results. Conversely, if the value of N is too small, there will be a large performance cost, so it is crucial to select the value of N reasonably.
[0055] Assume that the sampling frequency used in this application is every N instructions. The number of Gadget chains used in the ROP attack and the number of instructions contained in each Gadget are closely related to the sampling frequency. This application studies common ROP attacks to obtain the characteristics of common ROP attack chains. That is, to determine the difference between the ROP attack and the number of Gadget chains in a normal program and the number of instructions used in each Gadget in the ROP attack. Assume that the number of Gadget chains in a normal program is n, satisfying maxrop < n < minrop, where minrop is the minimum number of Gadgets that the ROP attack has at least, and maxrop is the maximum number of Gadgets in a normal program.
[0056] To determine the number of instructions used in each Gadget and the value of minrop, this application analyzed some actual ROP attacks. It was found that for most applications, the number of instructions contained in the Gadgets used in the ROP attack in actual situations is 6, and there are at least 17 Gadgets and at most 30 Gadgets. Therefore, the value of minrop selected in this application is 16.
[0057] To determine maxrop, this application used the ROPgadget-master[i] tool to construct ROP attacks on 200 application programs (such as svn, bzip2, netstat, etc.) in the folders / bin and / usr / bin. It can be found that 98% of these applications have less than 10 Gadgets, and only 2% have more than 10 Gadgets. Therefore, the value of maxrop selected in this application is 10.
[0058] Thus, the value of n should be between 11 and 16. To be able to detect some ROP attacks with fewer Gadgets, the value of n used in this application is 12. Through the above analysis, this application assumes that the ROP attack has the following characteristics:
[0059] The ROP attack contains at least 12 Gadgets;
[0060] The number of instructions contained in each Gadget is at least 6;
[0061] Most of these Gadgets end with the ret instruction.
[0062] Based on the characteristics of ROP attacks determined above, it can be found that ROP attacks generally only have 100-200 instructions, so the optimal sampling frequency is 100-200 instructions. If the sampling frequency is every 200 instructions, some characteristics of the program itself will affect the judgment of ROP attacks. At the same time, every 200 instructions does not significantly reduce the performance consumption brought by ROP detection. In order to improve the accuracy of ROP detection, the sampling frequency used in this application is every 100 instructions.
[0063] As a preferred embodiment of the present invention, specifically, every 100 instructions, four hardware events, namely, the executed call instruction, return instruction, the total number of branch prediction failures, and the number of conditional branch prediction failures, are recorded by creating a file descriptor through the function perf_event_open().
[0064] In the preferred embodiment, a file descriptor is created by the function perf_event_open() to allow recording of hardware events.
[0065] perf_event_open also provides two event monitoring modes: counting mode and sampling mode. In counting mode, the value of the event is read using the read function. In sampling mode, the value of the event is periodically written to a pre-specified buffer using the mmap function. The writing period is determined by the sampling frequency.
[0066] The following is an introduction to the various parameters of this function:
[0067] The parameters pid and cpu indicate which processes and CPUs are monitored, which are mainly divided into the following situations:
[0068] pid==0&&cpu==-1: monitor the current process on any CPU.
[0069] pid==0&&cpu>=0: Monitor the current process on the specified CPU.
[0070] pid>0&&cpu==-1: monitor the specified process on any CPU.
[0071] pid>0&&cpu>=0: Monitor the specified process on the specified CPU.
[0072] pid==-1&&cpu>=0: monitor all processes on the specified CPU.
[0073] pid==-1&&cpu==-1: illegal parameters.
[0074] The parameter group_fd allows the creation of event groups, that is, it allows multiple events to be recorded at the same time. The event group will have a group leader, which is first set by setting group_fd = -1.
[0075] The flags parameter is 0 or the following values:
[0076] PERF_FLAG_FD_CLOEXEC: Turn on the close-on-exec flag.
[0077] PERF_FLAG_FD_NO_GROPU: Ignore group_fd parameter
[0078] PERF_FLAG_FD_OUTPUT: Redirects the output of performance events in sampling mode, ignoring the pre-specified buffer.
[0079] The settings of each member in this application are shown in Table 1, where PERF_SAMPLE_IP indicates recording the value of EIP when a performance event occurs, and PERF_SAMPLE_READ indicates reading the value of the performance event counter. PERF_TYPE_HARDWARE in Type indicates recording hardware events, and PERF_TYPE_RAW indicates recording native events. The ones starting with r in config indicate native events, and the rest indicate hardware events. r2c4, r8c4, and r1c5 respectively indicate recording the number of call instructions executed, the number of ret instructions executed, and the number of conditional branch prediction failures. :u indicates that performance events are recorded only when the CPU is running in user mode.
[0080]
[0081]
[0082] Table 1
[0083] As a preferred embodiment of the present invention, specifically, the first threshold is 10 and the second threshold is 12.
[0084] As a preferred embodiment of the present invention, a method for obtaining the number of consecutive return branch prediction failures recorded in the LBR stack in two adjacent suspected ROP attack cycles includes:
[0085] The prediction of the current return branch is identified by obtaining the 63rd bit in MSR_LASTBRANCH_n_FROM_IP in the LBR stack. When the value of this bit is 1, it indicates that the return branch prediction failed, and when the value is 0, it indicates that the return branch prediction did not fail.
[0086] In this preferred embodiment, since some normal applications may also have characteristics similar to ROP attacks under certain circumstances, the present invention may generate false positives. In order to reduce false positives, the present invention combines the performance monitoring unit with the LBR stack to reduce the false positives generated.
[0087] The LBR stack can be used to record all types of branch transfers during program execution, or to record a combination of one or several different branches, such as recording call branches, ret branches, conditional branches separately, or recording call and ret branches at the same time.
[0088] This invention primarily considers ROP attacks constructed using the ret branch, so it only needs to record ret branch transfers. Since this invention only needs to record return branch transfers, it is necessary to use the MSR_LBR_SELECT register to specify and filter out other types of branch transfers. That is, in the Branch Type, only the RET bit is set to 0, indicating that all bits of other types of branches are 1. Similarly, this invention only needs to record return branch transfers in user mode, so the CPL of the MSR_LBR_SELECT register is set to EQ=1 to filter out return branch transfers when running in kernel mode.
[0089] The libpfm library makes it easy to record the contents of the LBR stack. Simply specify the event type to be recorded in sample_type as PERF_SAMPLE_BRANCH_STACK, set the branch to be recorded to PERF_SAMPLE_BRANCH_ANY_RETURN, and use a sampling frequency of 100 instructions.
[0090] The destination address of the return instruction executed by a normal program is generally the address of the instruction next to the call instruction. However, the return instruction executed in the ROP attack does not have a corresponding call instruction. Unlike kBouncer, the present invention does not need to detect whether the destination address of the return address is the address of the instruction next to the call instruction.
[0091] MSR_LASTBRANCH_n_FROM_IP has a special bit that can record the prediction of the current return branch. The 63rd bit in MSR_LASTBRANCH_n_FROM_IP identifies the prediction of the current return branch. When the bit value is 1, it indicates that the branch prediction failed, and when the value is 0, it indicates that there is no branch prediction failure. This shows that LBR records the prediction of the current branch while recording the branch transfer. We use this branch prediction to eliminate some false positives generated above. Even if the attacker uses call-preceded gadgets to construct a ROP attack, the method of the present invention can also detect it. At the same time, when a ROP attack occurs, the execution process of the attack can be traced based on the content in the LBR stack.
[0092] The return instruction executed in the ROP attack does not have a corresponding call instruction, which means that the return instruction executed in the ROP attack will cause a branch prediction failure. Therefore, it is possible to further determine whether a ROP attack exists based on the prediction of the return branch. The judgment is based on the following: if a ROP attack exists, then the number of consecutive return branch prediction failures will be greater than a threshold. Even if there are PMU records that meet the ROP attack judgment conditions, if there are return instructions among these large number of branch prediction failures and no prediction failures, it can be ruled out that a ROP attack has occurred. In acroread, it was found that according to the records (IIP: 0x000000b67d9d10 5 9 10 4, IIP: 0x000000085705ea 1 7 10 4), it can be determined that a ROP attack has occurred, resulting in a false alarm. When combined with the LBR stack, the content of the LBR stack corresponding to the record is obtained as follows: Figure 3 As shown in the figure, FROM represents the source address of the return branch, TO represents the destination address of the return branch, and MISPRED indicates whether the return branch failed to predict, indicating a 'Y' if it failed and an 'N' if it failed. The number of return instructions executed in record A is 9, so the LBR stack has 9 corresponding records. The number of return instructions executed in record B is 7, so the LBR stack has 7 records. Call-preceded is used to detect ROP attacks, as existing advanced ROP attacks can bypass this mechanism.
[0093] Aggregating these two instructions yields (12,10), where 12 represents the sum of branch prediction failures minus the number of conditional branch prediction failures, and 10 represents the sum of return instructions minus the number of call instructions. In this case, the probability that this record is judged to be a ROP attack is 0.7. However, when combined with the contents of the LBR stack, it is found that if a ROP attack exists, the return instructions executed by the ROP attack should be distributed in the first few records of the LBR stack in A and the last few records of the LBR stack in B, that is, the return instructions at these locations in A and B should have branch prediction failures, but Figure 3 The content in the LBR stack does not meet this condition, so it is determined to be a false positive.
[0094] To reduce false positives, this invention uses the number of consecutive return branch prediction failures as a feature of the decision tree. When aggregating two records, based on the characteristics of the LBR stack, the number of consecutive return branch prediction failures is obtained starting from the top of the stack for the first branch, and starting from the bottom of the stack for the second branch. Furthermore, in a normal program, a return branch may appear multiple times consecutively, but in a ROP attack, the same gadget is unlikely to appear consecutively. Therefore, this invention also uses the number of consecutive occurrences of the same gadget as a feature.
[0095] When PMU is combined with LBR to detect ROP attacks, the ROC curve obtained is as follows: Figure 2 As shown, the AUC score at this time is 0.97, that is, the detection rate of the method in the present invention is 97% when combined with the LBR stack. It can be seen that when combined with the LBR stack, the accuracy of ROP attack detection is greatly improved and false positives are reduced.
[0096] In summary, the ROP attack detection mechanism proposed in this invention, combined with LBR, can effectively detect ROP attacks with a performance cost of only 6%. Furthermore, compared to other methods, the method proposed in this invention does not rely on certain characteristics of ROP attacks, so it is applicable to most ROP attacks that use ret links.
[0097] As a preferred embodiment of the present invention, the method further includes, for a sampling period that is not marked as a suspected ROP attack period and whose first indicator is not less than a first threshold and whose second indicator is less than a second threshold, evenly dividing it into a plurality of combination periods according to the order of sampling time, assuming that there are N sampling periods in each combination period, that is, the length is NT, and recording the i-th combination period as {Cycle i 1. Cycle i2, ..., Cycle i N}, where Cycle i N represents the second indicator value of the Nth sampling period in the i-th combination period. Based on the changes in the second indicator values of adjacent combination periods, abnormal combination periods are found, and the sampling periods in the abnormal combination periods are marked as suspected ROP attack periods.
[0098] As a preferred embodiment of the present invention, specifically, finding abnormal combination periods based on changes in the second indicator values of adjacent combination periods includes:
[0099] Step 110: predefine loop variables and initialize i=1, then go to step 120;
[0100] Step 120: Obtain the i-th combined period as the i-th data set to be analyzed, and go to step 130;
[0101] Step 130: Determine whether i is equal to 1. If so, increase the value of i by 1 and go to step 120; if not, go to step 140.
[0102] Step 140: Perform change anomaly analysis based on the i-th data set to be analyzed and the i-1-th data set to be analyzed to obtain a change anomaly analysis result, and then go to step 150;
[0103] Step 150: If the abnormality analysis result of the i-th data set to be analyzed is abnormal, mark the abnormality and go to step 160 for execution; if no abnormality is found, go directly to step 160 for execution;
[0104] Step 160 , determine whether i is equal to N. If it is equal to N, output all abnormally marked data sets to be analyzed, that is, abnormal combination cycles. If it is not equal to N, increase the value of i by 1 and go to step 120 to execute.
[0105] As a preferred embodiment of the present invention, specifically, based on the i-th data set to be analyzed and the i-1-th data set to be analyzed, the abnormal change analysis result is obtained, including:
[0106] The i-1th data set to be analyzed is {Cycle i-1 1. Cycle i-1 2, ..., Cycle i-1 N}, Cycle i-1 j represents the jth element in the i-1th data set to be analyzed, and the value range of j is [1, N];
[0107] Take the i-1th data set to be analyzed {Cycle i-1 1. Cycle i-1 2, ..., Cyclei-1 Any element in N}Cycle i-1 The element number j of j is used as the horizontal axis, Cycle i-1 The value of j is used as the ordinate to obtain N data points in the two-dimensional coordinate system;
[0108] The N data points in the two-dimensional coordinate system are processed by a fitting algorithm to obtain the change representation curve of the i-1th data set to be analyzed, which is recorded as the change representation curve i-1;
[0109] The i-th data set to be analyzed is {Cycle i 1. Cycle i 2, ..., Cycle i N}, Cycle i j represents the jth element in the i-th data set to be analyzed;
[0110] Take the i-th data set to be analyzed {Cycle i 1. Cycle i 2, ..., Cycle i Any element in N}Cycle i The element number j of j is used as the horizontal axis, Cycle i The value of j is used as the y coordinate to obtain N data points located in the two-dimensional coordinate system;
[0111] Calculate the nearest distance values of these N data points to the change representation curve i-1 respectively and integrate them to obtain the nearest distance value sequence corresponding to the i-th data set to be analyzed {Cycle i zj1, Cycle i zj2, ..., Cycle i zjN}, Cycle i _zjj represents the jth element in the sequence of the closest distance values corresponding to the i-th data set to be analyzed;
[0112] Traverse {Cycle i zj1, Cycle i zj2, ..., Cycle i zjN}, count the number of elements M that exceed the fourth threshold;
[0113] It is determined whether the value of M is greater than a fifth threshold. If so, it is marked that the i-th data set to be analyzed has an abnormal change. If not, it is determined that the i-th data set to be analyzed has no abnormal change.
[0114] In this preferred embodiment, considering that the second indicator, i.e., the total number of branch prediction failures minus the number of conditional branch prediction failures, should not change much within a certain range, if the second indicator shows the above-mentioned abnormal changes, then these sampling periods (i.e., all sampling periods contained in the data set to be analyzed with abnormal changes) will also be analyzed as suspected ROP attack periods to ensure accurate ROP attack detection.
[0115] In Example 2, the present invention further proposes a device for detecting ROP attacks based on hardware characteristics, comprising the following:
[0116] A first data acquisition module is configured to acquire hardware event records of instruction data according to a preset sampling period T, wherein the hardware events include the number of call instructions executed in the instruction data, the number of return instructions executed, the total number of branch prediction failures, and the number of conditional branch prediction failures;
[0117] an indicator calculation module, configured to calculate a first indicator and a second indicator based on its hardware event records in any sampling period, wherein the first indicator is the number of return instructions minus the number of call instructions, and the second indicator is the total number of branch prediction failures minus the number of conditional branch prediction failures;
[0118] A first judgment module is configured to directly determine whether a ROP attack does not exist in the sampling period if the first indicator is less than a first threshold; if the first indicator is not less than the first threshold, determine whether the second indicator is not less than a second threshold; and if the second indicator is not less than the second threshold, mark the sampling period as a suspected ROP attack period;
[0119] The second data acquisition module is used to obtain the number of consecutive return branch prediction failures recorded in the LBR stack in two adjacent suspected ROP attack cycles;
[0120] The second judgment module is used to judge that there is no ROP attack in the two suspected ROP attack cycles if the number of consecutive return branch prediction failures is greater than a third threshold; if not, judge that there is a ROP attack in the two suspected ROP attack cycles.
[0121] In addition, the functional modules in various embodiments of the present invention may be integrated into a single processing module, or each module may exist physically separately, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or software functional modules.
[0122] If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention implements all or part of the process in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or system that can carry the computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal and software distribution medium, etc.
[0123] Although the present invention has been described in considerable detail and with particularity with respect to several described embodiments, it is not intended to be limited to any of these details or embodiments or any particular embodiment, but rather should be construed as providing a broad possible interpretation of these claims in view of the prior art by reference to the appended claims, thereby effectively encompassing the intended scope of the invention. In addition, the invention has been described above in terms of embodiments foreseen by the inventors for the purpose of providing a useful description, and those insubstantial modifications of the invention that are not currently foreseen may still represent equivalent modifications of the invention.
[0124] The above description is merely a preferred embodiment of the present invention. The present invention is not limited to the above-described embodiments. As long as the technical effects of the present invention are achieved by the same means, they shall fall within the scope of protection of the present invention. Within the scope of protection of the present invention, various modifications and variations of the technical solutions and / or implementation methods may be made.
Claims
1. A ROP attack detection method based on hardware characteristics, characterized in that: These include: Acquire hardware event records of instruction data according to a preset sampling period T, wherein the hardware events include the number of call instructions executed in the instruction data, the number of return instructions, the total number of branch prediction failures, and the number of conditional branch prediction failures; In any sampling period, based on its hardware event records, a first metric and a second metric are calculated, wherein the first metric is the number of return instructions minus the number of call instructions, and the second metric is the total number of branch prediction failures minus the number of conditional branch prediction failures; If the first indicator is less than the first threshold, it is directly determined that there is no ROP attack in the sampling period. If the first indicator is not less than the first threshold, it is determined whether the second indicator is not less than the second threshold. If the second indicator is not less than the second threshold, the sampling period is marked as a suspected ROP attack period. Obtain the number of consecutive return branch prediction failures recorded in the LBR stack in two adjacent suspected ROP attack cycles; If the number of consecutive return branch prediction failures is greater than the third threshold, it is determined that no ROP attack exists in the two suspected ROP attack cycles; if it is not greater than the third threshold, it is determined that a ROP attack exists in the two suspected ROP attack cycles.
2. The ROP attack detection method based on hardware characteristics according to claim 1 is characterized in that: Specifically, every 100 instructions, four hardware events, namely, the executed call instruction, return instruction, the total number of branch prediction failures, and the number of conditional branch prediction failures, are recorded by creating a file descriptor through the function perf_event_open().
3. The ROP attack detection method based on hardware characteristics according to claim 1 is characterized in that: Specifically, the first threshold is 10 and the second threshold is 12.
4. The ROP attack detection method based on hardware characteristics according to claim 1 is characterized in that: Methods for obtaining the number of consecutive return branch prediction failures recorded in the LBR stack in two adjacent suspected ROP attack cycles include: The prediction of the current return branch is identified by obtaining the 63rd bit in MSR_LASTBRANCH_n_FROM_IP in the LBR stack. When the value of this bit is 1, it indicates that the return branch prediction failed, and when the value is 0, it indicates that the return branch prediction did not fail.
5. The ROP attack detection method based on hardware characteristics according to claim 1 is characterized in that: The method further includes, for a sampling period that is not marked as a suspected ROP attack period and has a first indicator not less than a first threshold and a second indicator less than a second threshold, evenly dividing the sampling period into a plurality of combination periods according to the order of sampling time, assuming that each combination period has N sampling periods, i.e., a length of NT, and recording the i-th combination period as {Cycle i 1. Cycle i 2, ..., Cycle i N}, where Cycle i N represents the second indicator value of the Nth sampling period in the i-th combination period. Based on the changes in the second indicator values of adjacent combination periods, abnormal combination periods are found, and the sampling periods in the abnormal combination periods are marked as suspected ROP attack periods.
6. The ROP attack detection method based on hardware characteristics according to claim 5 is characterized in that: Specifically, the abnormal combination period is found based on the change of the second indicator value of the adjacent combination period, including: Step 110: predefine loop variables and initialize i=1, then go to step 120; Step 120: Obtain the i-th combined period as the i-th data set to be analyzed, and go to step 130; Step 130: Determine whether i is equal to 1. If so, increase the value of i by 1 and go to step 120; if not, go to step 140. Step 140: Perform change anomaly analysis based on the i-th data set to be analyzed and the i-1-th data set to be analyzed to obtain a change anomaly analysis result, and then go to step 150; Step 150: If the abnormality analysis result of the i-th data set to be analyzed is abnormal, mark the abnormality and go to step 160 for execution; if no abnormality is found, go directly to step 160 for execution; Step 160 , determine whether i is equal to N. If it is equal to N, output all abnormally marked data sets to be analyzed, that is, abnormal combination cycles. If it is not equal to N, increase the value of i by 1 and go to step 120 to execute.
7. The ROP attack detection method based on hardware characteristics according to claim 6, characterized in that: Specifically, based on the i-th data set to be analyzed and the i-1-th data set to be analyzed, the abnormal change analysis results are obtained, including: The i-1th data set to be analyzed is {Cycle i-1 1. Cycle i-1 2, ..., Cycle i-1 N}, Cycle i-1 j represents the jth element in the i-1th data set to be analyzed, and the value range of j is [1, N]; Take the i-1th data set to be analyzed {Cycle i-1 1. Cycle i-1 2, ..., Cycle i-1 Any element in N}Cycle i-1 The element number j of j is used as the horizontal axis, Cycle i-1 The value of j is used as the ordinate to obtain N data points in the two-dimensional coordinate system; The N data points in the two-dimensional coordinate system are processed by a fitting algorithm to obtain the change representation curve of the i-1th data set to be analyzed, which is recorded as the change representation curve i-1; The i-th data set to be analyzed is {Cycle i 1. Cycle i 2, ..., Cycle i N}, Cycle i j represents the jth element in the i-th data set to be analyzed; Take the i-th data set to be analyzed {Cycle i 1. Cycle i 2, ..., Cycle i Any element in N}Cycle i The element number j of j is used as the horizontal axis, Cycle i The value of j is used as the y coordinate to obtain N data points located in the two-dimensional coordinate system; Calculate the nearest distance values of these N data points to the change representation curve i-1 respectively and integrate them to obtain the nearest distance value sequence corresponding to the i-th data set to be analyzed {Cycle i zj1, Cycle i zj2, ..., Cycle i zjN}, Cycle i _zjj represents the jth element in the sequence of the closest distance values corresponding to the i-th data set to be analyzed; Traverse {Cycle i zj1, Cycle i zj2, ..., Cycle i zjN}, count the number of elements M that exceed the fourth threshold; It is determined whether the value of M is greater than a fifth threshold. If so, it is marked that the i-th data set to be analyzed has an abnormal change. If not, it is determined that the i-th data set to be analyzed has no abnormal change.
8. A device for detecting ROP attacks based on hardware characteristics, characterized in that: These include: A first data acquisition module is configured to acquire hardware event records of instruction data according to a preset sampling period T, wherein the hardware events include the number of call instructions executed in the instruction data, the number of return instructions executed, the total number of branch prediction failures, and the number of conditional branch prediction failures; an indicator calculation module, configured to calculate a first indicator and a second indicator based on its hardware event records in any sampling period, wherein the first indicator is the number of return instructions minus the number of call instructions, and the second indicator is the total number of branch prediction failures minus the number of conditional branch prediction failures; A first judgment module is configured to directly determine whether a ROP attack does not exist in the sampling period if the first indicator is less than a first threshold; if the first indicator is not less than the first threshold, determine whether the second indicator is not less than a second threshold; and if the second indicator is not less than the second threshold, mark the sampling period as a suspected ROP attack period; The second data acquisition module is used to obtain the number of consecutive return branch prediction failures recorded in the LBR stack in two adjacent suspected ROP attack cycles; The second judgment module is used to judge that there is no ROP attack in the two suspected ROP attack cycles if the number of consecutive return branch prediction failures is greater than a third threshold; if not, judge that there is a ROP attack in the two suspected ROP attack cycles.
Citation Information
Patent Citations
A method and apparatus for detecting tampering with program stream attacks
CN109508536A
ROP and variant attack dynamic detection method based on multi-strategy instruction detection
CN109766690A
A method for detecting a Cache attack in real time
CN109918901A
Detection method for Cache side channel attack in multi-core processor
CN118349995A
Apparatus and method for detecting code reuse attack
KR1020180039830A