MARDU: Efficient and Scalable Code Re-randomization

7Citations
Citations of this article
7Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Defense techniques such as Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) were role models in preventing early return-oriented programming (ROP) attacks by keeping performance and scalability in the forefront, making them widely-adopted. As code reuse attacks evolved in complexity, defenses have lost touch with pragmatic defense design to ensure security, either being narrow in scope or providing unrealistic overheads. We present MARDU, an on-demand system-wide re-randomization technique that maintains strong security guarantees while providing better overall performance and having scalability most defenses lack. We achieve code sharing with diversification by implementing reactive and scalable, rather than continuous or one-time diversification. Enabling code sharing further minimizes needed tracking, patching, and memory overheads. The evaluation of MARDU shows low performance overhead of 5.5% on SPEC and minimal degradation of 4.4% in NGINX, proving its applicability to both compute-intensive and scalable real-world applications.

Cite

CITATION STYLE

APA

Jelesnianski, C., Yom, J., Min, C., & Jang, Y. (2020). MARDU: Efficient and Scalable Code Re-randomization. In SYSTOR 2020 - Proceedings of the 13th ACM International Systems and Storage Conference (pp. 49–60). Association for Computing Machinery. https://doi.org/10.1145/3383669.3398280

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free