{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T23:17:03Z","timestamp":1784330223152,"version":"3.55.0"},"publisher-location":"Cham","reference-count":24,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031541285","type":"print"},{"value":"9783031541292","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-54129-2_22","type":"book-chapter","created":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:03:15Z","timestamp":1710194595000},"page":"377-391","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Execution at\u00a0RISC: Stealth JOP Attacks on\u00a0RISC-V Applications"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-4848-1478","authenticated-orcid":false,"given":"Lo\u00efc","family":"Buckwell","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3776-2071","authenticated-orcid":false,"given":"Olivier","family":"Gilles","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5364-8244","authenticated-orcid":false,"given":"Daniel Gracia","family":"P\u00e9rez","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1557-2813","authenticated-orcid":false,"given":"Nikolai","family":"Kosmatov","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,3,12]]},"reference":[{"key":"22_CR1","doi-asserted-by":"publisher","unstructured":"Abadi, M., Budiu, M., Erlingsson, U., Ligatti, J.: Control-flow integrity. In: the 12th ACM Conference on Computer and Communications Security (CCS\u201905), pp. 340\u2013353. ACM (2005). https:\/\/doi.org\/10.1145\/1102120.1102165","DOI":"10.1145\/1102120.1102165"},{"key":"22_CR2","unstructured":"Brizendine, B., Babcock, A.: Pre-built JOP chains with the JOP ROCKET: bypassing DEP without ROP. In: Black Hat Asia, May 2021"},{"key":"22_CR3","doi-asserted-by":"publisher","unstructured":"Burow, N., et al.: Control-flow integrity: precision, security, and performance. ACM Comput. Surv. 50(1) (2017). https:\/\/doi.org\/10.1145\/3054924","DOI":"10.1145\/3054924"},{"key":"22_CR4","unstructured":"Carlini, N., Wagner, D.: ROP is still dangerous: breaking modern defenses. In: the 23rd USENIX Conference on Security Symposium (SEC\u201914), pp. 385\u2013399. USENIX Association (2014)"},{"key":"22_CR5","doi-asserted-by":"publisher","unstructured":"Checkoway, S., Davi, L., Dmitrienko, A., Sadeghi, A.R., Shacham, H., Winandy, M.: Return-oriented programming without returns. In: the 17th ACM Conference on Computer and Communications Security (CCS\u201910), pp. 559\u2013572. ACM (2010). https:\/\/doi.org\/10.1145\/1866307.1866370","DOI":"10.1145\/1866307.1866370"},{"key":"22_CR6","unstructured":"Cowan, C.: StackGuard: automatic adaptive detection and prevention of buffer-overflow attacks. In: the 7th USENIX Security Symposium. USENIX Association (1998)"},{"key":"22_CR7","doi-asserted-by":"publisher","unstructured":"De, A., Ghosh, S.: HeapSafe: securing unprotected heaps in RISC-V. In: the 35th International Conference on VLSI Design and the 21st International Conference on Embedded Systems (VLSID\u201922), pp. 120\u2013125. IEEE (2022). https:\/\/doi.org\/10.1109\/VLSID2022.2022.00034","DOI":"10.1109\/VLSID2022.2022.00034"},{"key":"22_CR8","doi-asserted-by":"publisher","unstructured":"Erd\u00f6di, L.: Finding dispatcher gadgets for jump oriented programming code reuse attacks. In: the 8th International Symposium on Applied Computational Intelligence and Informatics (SACI\u201913), pp. 321\u2013325. IEEE (2013). https:\/\/doi.org\/10.1109\/SACI.2013.6608990","DOI":"10.1109\/SACI.2013.6608990"},{"key":"22_CR9","doi-asserted-by":"publisher","unstructured":"Evtyushkin, D., Ponomarev, D., Abu-Ghazaleh, N.: Jump over ASLR: attacking branch predictors to bypass ASLR. In: the 49th Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO\u201916), pp. 40:1\u201340:13. IEEE (2016). https:\/\/doi.org\/10.1109\/MICRO.2016.7783743","DOI":"10.1109\/MICRO.2016.7783743"},{"key":"22_CR10","doi-asserted-by":"publisher","unstructured":"Gilles, O., Viguier, F., Kosmatov, N., Gracia P\u00e9rez, D.: Control-flow integrity at RISC: attacking RISC-V by jump-oriented programming. CoRR (2022). https:\/\/doi.org\/10.48550\/arXiv.2211.16212","DOI":"10.48550\/arXiv.2211.16212"},{"key":"22_CR11","doi-asserted-by":"crossref","unstructured":"Gras, B., Razavi, K., Bosman, E., Bos, H., Giuffrida, C.: ASLR on the line: practical cache attacks on the MMU. In: the 24th Annual Network and Distributed System Security Symposium (NDSS\u201917). The Internet Society (2017)","DOI":"10.14722\/ndss.2017.23271"},{"key":"22_CR12","unstructured":"Gu, G., Shacham, H.: Return-oriented programming in RISC-V. CoRR (2020). https:\/\/arxiv.org\/abs\/2007.14995"},{"key":"22_CR13","doi-asserted-by":"publisher","unstructured":"Harris, A., et al.: Morpheus II: a RISC-V security extension for protecting vulnerable software and hardware. In: the IEEE International Symposium on Hardware Oriented Security and Trust (HOST\u201921), pp. 226\u2013238. IEEE (2021). https:\/\/doi.org\/10.1109\/HOST49136.2021.9702275","DOI":"10.1109\/HOST49136.2021.9702275"},{"key":"22_CR14","doi-asserted-by":"publisher","unstructured":"Jaloyan, G.A., Markantonakis, K., Akram, R.N., Robin, D., Mayes, K., Naccache, D.: Return-oriented programming on RISC-V. In: the 15th ACM Asia Conference on Computer and Communications Security (ASIA CCS\u201920), pp. 471\u2013480. ACM (2020). https:\/\/doi.org\/10.1145\/3320269.3384738","DOI":"10.1145\/3320269.3384738"},{"key":"22_CR15","unstructured":"Lu, T.: A survey on RISC-V security: Hardware and architecture. CoRR (2021). https:\/\/arxiv.org\/abs\/2107.04175"},{"key":"22_CR16","doi-asserted-by":"publisher","unstructured":"Nurmukhametov, A., Vishnyakov, A., Logunova, V., Kurmangaleev, S.F.: MAJORCA: multi-architecture JOP and ROP chain assembler. In: the 2021 Ivannikov Ispras Open Conference (ISPRAS\u201921), pp. 37\u201346 (2021). https:\/\/doi.org\/10.1109\/ISPRAS53967.2021.00011","DOI":"10.1109\/ISPRAS53967.2021.00011"},{"key":"22_CR17","doi-asserted-by":"publisher","unstructured":"Palmiero, C., Di Guglielmo, G., Lavagno, L., Carloni, L.P.: Design and implementation of a dynamic information flow tracking architecture to secure a RISC-V core for IoT applications. In: the 2018 IEEE High Performance Extreme Computing Conference (HPEC\u201918), pp. 1\u20137. IEEE (2018). https:\/\/doi.org\/10.1109\/HPEC.2018.8547578","DOI":"10.1109\/HPEC.2018.8547578"},{"key":"22_CR18","doi-asserted-by":"publisher","unstructured":"Sadeghi, A.A., Aminmansour, F., Shahriari, H.R.: Tazhi: a novel technique for hunting trampoline gadgets of jump oriented programming (a class of code reuse attacks). In: the 2014 11th International ISC Conference on Information Security and Cryptology, pp. 21\u201326 (2014). https:\/\/doi.org\/10.1109\/ISCISC.2014.6994016","DOI":"10.1109\/ISCISC.2014.6994016"},{"key":"22_CR19","doi-asserted-by":"publisher","unstructured":"Shacham, H.: The geometry of innocent flesh on the bone: return-into-libc without function calls (on the x86). In: the 2007 ACM Conference on Computer and Communications Security (CCS\u201907), pp. 552\u2013561. ACM (2007). https:\/\/doi.org\/10.1145\/1315245.1315313","DOI":"10.1145\/1315245.1315313"},{"key":"22_CR20","doi-asserted-by":"publisher","unstructured":"Shacham, H., Page, M., Pfaff, B., Goh, E.J., Modadugu, N., Boneh, D.: On the effectiveness of address-space randomization. In: the 11th ACM Conference on Computer and Communications Security (CCS\u201904), pp. 298\u2013307. ACM (2004). https:\/\/doi.org\/10.1145\/1030083.1030124","DOI":"10.1145\/1030083.1030124"},{"key":"22_CR21","unstructured":"Solar Designer: Getting around non-executable stack (and fix) (1997). https:\/\/seclists.org\/bugtraq\/1997\/Aug\/63"},{"key":"22_CR22","doi-asserted-by":"publisher","first-page":"271","DOI":"10.1134\/S0361768821040071","volume":"47","author":"A Vishnyakov","year":"2021","unstructured":"Vishnyakov, A., Nurmukhametov, A.: Survey of methods for automated code-reuse exploit generation. Program. Comput. Softw. 47, 271\u2013297 (2021). https:\/\/doi.org\/10.1134\/S0361768821040071","journal-title":"Program. Comput. Softw."},{"key":"22_CR23","unstructured":"Younan, Y., Joosen, W., Piessens, F.: Code injection in C and C++: a survey of vulnerabilities and countermeasures. Technical report, Department Computer wetenschappen, Katholieke Universiteit Leuven (2004). https:\/\/www.cs.kuleuven.be\/publicaties\/rapporten\/cw\/CW386.pdf"},{"key":"22_CR24","doi-asserted-by":"publisher","unstructured":"Zaruba, F., Benini, L.: The cost of application-class processing: energy and performance analysis of a Linux-ready 1.7-GHz 64-bit RISC-V core in 22-nm FDSOI technology. IEEE Trans. Very Large Scale Integr. Syst. 27(11), 2629\u20132640 (2019). https:\/\/doi.org\/10.1109\/TVLSI.2019.2926114","DOI":"10.1109\/TVLSI.2019.2926114"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2023 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-54129-2_22","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:06:24Z","timestamp":1710194784000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-54129-2_22"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031541285","9783031541292"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-54129-2_22","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"12 March 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Hague","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 September 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2023.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"478","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"93","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"10","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}