DAEDALUS: Defense Against Firmware ROP Exploits Using Stochastic Software Diversity

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Obaidat, Islam, Sridhar, Meera, Tavakoli, Fatemeh
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911766803382272
author Obaidat, Islam
Sridhar, Meera
Tavakoli, Fatemeh
author_facet Obaidat, Islam
Sridhar, Meera
Tavakoli, Fatemeh
contents This paper presents DAEDALUS, a software diversity-based framework designed to resist ROP attacks on Linux-based IoT devices. DAEDALUS generates unique, semantically equivalent but syntactically different rewrites of IoT firmware, disrupting large-scale replication of ROP attacks. DAEDALUS employs STOKE, a stochastic optimizer for x86 binaries, as its core diversity engine but introduces significant extensions to address unique IoT firmware challenges. DAEDALUS's effectiveness is evaluated using DDoSim, a published botnet DDoS attack simulation testbed. Results demonstrate that DAEDALUS successfully neutralizes ROP payloads by diversifying critical basic blocks in the firmware, preventing attackers from compromising multiple devices for DDoS attacks via memory error vulnerabilities. The findings indicate that DAEDALUS not only mitigates the impact of ROP attacks on individual IoT devices through probabilistic protection but also thwarts large-scale ROP attacks across multiple devices.
format Preprint
id arxiv_https___arxiv_org_abs_2401_16234
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle DAEDALUS: Defense Against Firmware ROP Exploits Using Stochastic Software Diversity
Obaidat, Islam
Sridhar, Meera
Tavakoli, Fatemeh
Cryptography and Security
This paper presents DAEDALUS, a software diversity-based framework designed to resist ROP attacks on Linux-based IoT devices. DAEDALUS generates unique, semantically equivalent but syntactically different rewrites of IoT firmware, disrupting large-scale replication of ROP attacks. DAEDALUS employs STOKE, a stochastic optimizer for x86 binaries, as its core diversity engine but introduces significant extensions to address unique IoT firmware challenges. DAEDALUS's effectiveness is evaluated using DDoSim, a published botnet DDoS attack simulation testbed. Results demonstrate that DAEDALUS successfully neutralizes ROP payloads by diversifying critical basic blocks in the firmware, preventing attackers from compromising multiple devices for DDoS attacks via memory error vulnerabilities. The findings indicate that DAEDALUS not only mitigates the impact of ROP attacks on individual IoT devices through probabilistic protection but also thwarts large-scale ROP attacks across multiple devices.
title DAEDALUS: Defense Against Firmware ROP Exploits Using Stochastic Software Diversity
topic Cryptography and Security
url https://arxiv.org/abs/2401.16234