Memory behaviour based models for program integrity verification and anomaly detection against code reuse attacks

dc.contributor.guideShanthi A P
dc.coverage.spatialMemory behaviour based models for program integrity verification and anomaly detection against code reuse attacks
dc.creator.researcherDileesh E D
dc.date.accessioned2023-06-07T09:23:33Z
dc.date.available2023-06-07T09:23:33Z
dc.date.awarded2022
dc.date.completed2022
dc.date.registered
dc.description.abstractReliability and usefulness of any computing system relies on the integrity newlineand correctness of the code running in the system. Any adversarial modification in newlinethe code causes execution integrity violations in the system, and causes behaviour newlineanomalies. The code may be modified statically using code injection methods or newlinealtered dynamically at run-time, to create attacks against the computing systems. newlineTechniques to detect the execution integrity violations rely on static newlinecode analysis models like Control Flow Integrity (CFI) solutions, taint tracking newlineand hardware based trusted computing platforms. CFI schemes keep the list newlineof valid control-flow target addresses as eligible target sets, and these target newlineaddresses are verified on each execution of the direct or indirect control transfer newlineinstructions, during execution. Taint tracking method intentionally insert some newlinespecial data-structures into the code at compile time, and the behaviour of these newlinedata structures are verified during execution. Trusted computing platforms ensure newlinecode integrity, but with the cost of additional hardware and storage. Even though newlinebasic CFI schemes are widely adopted in many systems, these techniques do not newlinepreserve Time Of Check To Time Of Use (TOCTTOU) consistency. Also, there newlineexist more advanced and application specific code reuse attack strategies like Data newlineOriented Programming (DOP) that bypass CFI checks. Solutions that deal with newlinethese types of attacks require compiler or hardware support and modifications. newlineThis thesis proposes strategies to detect run-time anomalies without any newlinehardware or software modification in the underlying machine or the application newlinecode. The broad objective of the thesis is to build a behaviour model that newlinedetects run- time anomalies in applications. The specific objective is to detect newlinethe non-control- data attacks created using Return Oriented Pro newline
dc.description.note
dc.format.accompanyingmaterialNone
dc.format.dimensions21 cms
dc.format.extentxiv, 113p.
dc.identifier.urihttp://hdl.handle.net/10603/489726
dc.languageEnglish
dc.publisher.institutionFaculty of Information and Communication Engineering
dc.publisher.placeChennai
dc.publisher.universityAnna University
dc.relationp.103-112
dc.rightsuniversity
dc.source.universityUniversity
dc.subject.keywordEngineering and Technology
dc.subject.keywordComputer Science
dc.subject.keywordComputer Science Artificial Intelligence
dc.subject.keywordrun- time anomalies
dc.subject.keywordControl Flow Integrity
dc.subject.keywordReliability
dc.titleMemory behaviour based models for program integrity verification and anomaly detection against code reuse attacks
dc.title.alternative
dc.type.degreePh.D.

Files

Original bundle

Now showing 1 - 5 of 11
Loading...
Thumbnail Image
Name:
01_title.pdf
Size:
191.41 KB
Format:
Adobe Portable Document Format
Description:
Attached File
Loading...
Thumbnail Image
Name:
02_prelim.pdf
Size:
1.13 MB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
03_content.pdf
Size:
75.32 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
04_abstract.pdf
Size:
48.4 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
05_chapter 1.pdf
Size:
119.89 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.79 KB
Format:
Plain Text
Description: