{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,26]],"date-time":"2025-02-26T05:17:21Z","timestamp":1740547041516,"version":"3.38.0"},"reference-count":50,"publisher":"EDP Sciences","license":[{"start":{"date-parts":[[2025,1,30]],"date-time":"2025-01-30T00:00:00Z","timestamp":1738195200000},"content-version":"vor","delay-in-days":29,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Security and Safety"],"accepted":{"date-parts":[[2024,10,15]]},"published-print":{"date-parts":[[2025]]},"abstract":"<jats:p>As modern systems widely deploy protective measures for control data in memory, such as Control-Flow Integrity (CFI), attackers\u2019 ability to manipulate control data is greatly restricted. Consequently, attackers are turning to opportunities to manipulate non-control data in memory (known as Data-Oriented Attacks, or DOAs), which have been proven to pose significant security threats to memory. However, existing techniques to mitigate DOAs often introduce significant overhead due to the indiscriminate protection of a large range of data objects. To address this challenge, this paper adopts a Cyberspace Mimic Defense (CMD) strategy, a generic framework for addressing endogenous security vulnerabilities, to prevent attackers from executing DOAs using known or unknown security flaws. Specifically, we introduce a formalized expression algorithm that assesses whether DOA attackers can construct inputs to exploit vulnerability points. Building on this, we devise a key-area CMD strategy that modifies the coded pathway from input to the vulnerability point, thereby effectively thwarting the activation of the vulnerability. Finally, our experiments on real-world applications and simulation demonstrate that the key-area CMD strategy can effectively prevent DOAs by selectively diversifying parts of the program code.<\/jats:p>","DOI":"10.1051\/sands\/2024015","type":"journal-article","created":{"date-parts":[[2024,10,16]],"date-time":"2024-10-16T11:49:10Z","timestamp":1729079350000},"page":"2024015","source":"Crossref","is-referenced-by-count":0,"title":["Key-area cyberspace mimic defense against data-oriented attacks"],"prefix":"10.1051","volume":"4","author":[{"given":"Ping","family":"Chen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jin","family":"Wei","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhuyang","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-4954-068X","authenticated-orcid":false,"given":"Jiwei","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"250","published-online":{"date-parts":[[2025,1,30]]},"reference":[{"key":"R1","doi-asserted-by":"crossref","unstructured":"Wu JX. Cyberspace endogenous safety and security, Engineering 2021, in press, https:\/\/doi.org\/10.1016\/j.eng.2021.05.015.","DOI":"10.1016\/j.eng.2021.05.015"},{"key":"R2","unstructured":"Dahl WA, Erdodi L and Zennaro FM. Stack-based buffer overflow detection using recurrent neural networks 2020, ArXiv preprint [arXiv: https:\/\/arxiv.org\/abs\/2012.15116]."},{"key":"R3","unstructured":"Jia X, Zhang C and Su P et al. Towards efficient heap overflow discovery. In: 26th USENIX Security Symposium, USENIX Security, 2017, 989\u20131006."},{"key":"R4","doi-asserted-by":"crossref","unstructured":"Snow KZ, Monrose F and Davi L et al. Just-in-time code reuse: On the effectiveness of fine-grained address space layout randomization. In: IEEE Symposium on Security and Privacy, 2013.","DOI":"10.1109\/SP.2013.45"},{"key":"R5","doi-asserted-by":"crossref","unstructured":"Bittau A, Belay A and Mashtizadeh A et al. Hacking blind. In: 2014 IEEE Symposium on Security and Privacy. IEEE, 2014, 227\u2013242","DOI":"10.1109\/SP.2014.22"},{"key":"R6","unstructured":"Chen S, Xu J and Sezer EC et al. Non-control-data attacks are realistic threats. USENIX Secur Symp 2005; 5: 146."},{"key":"R7","doi-asserted-by":"crossref","unstructured":"Hu H, Shinde S and Adrian S et al. Data-oriented programming: On the expressiveness of non-control data attacks. In: 2016 IEEE Symposium on Security and Privacy (SP), IEEE, 2016, 969\u2013986.","DOI":"10.1109\/SP.2016.62"},{"key":"R8","doi-asserted-by":"crossref","unstructured":"Hu H, Qian C and Yagemann C et al. Enforcing unique code target property for control-flow integrity. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, 2018, 1470\u20131486.","DOI":"10.1145\/3243734.3243797"},{"key":"R9","unstructured":"Khandaker MR, Liu W and Naser A et al. Origin-sensitive control flow integrity. In: 28th USENIX Security Symposium (USENIX Security 19), 2019, 195\u2013211."},{"key":"R10","unstructured":"Bhatkar S and Sekar R. Data Space Randomization. Springer: Berlin, Heidelberg, 2008."},{"key":"R11","unstructured":"Cadar C, Akritidis P, Costa M, Martin JP and Castro M. Data randomization, Technical Report, Technical Report TR-2008-120, Microsoft Research, 2008."},{"key":"R12","doi-asserted-by":"crossref","unstructured":"Rajasekaran P, Crane S, Gens D, Na Y, Volckaert S and Franz M. CoDaRR: Continuous data space randomization against data-only attacks. In: Proceedings of the 15th ACM Asia Conference on Computer and Communications Security, 2020, 494\u2013505.","DOI":"10.1145\/3320269.3384757"},{"key":"R13","doi-asserted-by":"crossref","unstructured":"Lin Z, Riley RD and Xu D. Polymorphing software by randomizing data structure layout. In: Proceedings of Detection of Intrusions and Malware, and Vulnerability Assessment: 6th International Conference, DIMVA 2009, Como, Italy, July 9\u201310, 2009. Proceedings 6, Springer, 2009, 107\u2013126.","DOI":"10.1007\/978-3-642-02918-9_7"},{"key":"R14","doi-asserted-by":"crossref","unstructured":"Chen P, Xu J, Lin Z, Xu D, Mao B and Liu P. A practical approach for adaptive data structure layout randomization. In: Proceedings of Computer Security\u2013ESORICS 2015: 20th European Symposium on Research in Computer Security, Vienna, Austria, September 21\u201325, 2015, Proceedings, Part I 20, Springer, 2015, 69\u201389.","DOI":"10.1007\/978-3-319-24174-6_4"},{"key":"R15","unstructured":"Radford A, Karthik Narasimhan, Salimans T and Sutskever I. Improving language understanding by generative pre-training, 2018."},{"key":"R16","unstructured":"Devlin J, Chang M-W, Lee K and Toutanova K. Bert: Pre-training of Deep Bidirectional Transformers for Language Understanding, 2018, ArXiv preprint [arXiv: https:\/\/arxiv.org\/abs\/1810.04805]."},{"key":"R17","doi-asserted-by":"crossref","unstructured":"Wu J. Cyberspace mimic defense. Cham: Springer International Publishing, 2020.","DOI":"10.1007\/978-3-030-29844-9"},{"key":"R18","first-page":"58","volume":"11","author":"Nergal","year":"2001","journal-title":"Phrack Mag"},{"key":"R19","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2133375.2133377","volume":"15","author":"Roemer","year":"2012","journal-title":"ACM Trans Inf Syst Security (TISSEC)"},{"key":"R20","doi-asserted-by":"crossref","unstructured":"Bletsch T, Jiang X and Freeh VW, et al. Jump-oriented programming: a new class of code-reuse attack. In: Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, 2011, 30\u201340.","DOI":"10.1145\/1966913.1966919"},{"key":"R21","unstructured":"PaX. Homepage of The PaX Team, 2001, http:\/\/pax.grsecurity.net."},{"key":"R22","unstructured":"Sadeghipourrudsari M, Prinetto P and Nouri E et al. A Secure Canary-Based Hardware Approach Against ROP. In: Title of the volume not validated. CEUR Workshop Proceedings, 2022, 6."},{"key":"R23","unstructured":"Team P. PaX address space layout randomization, 2003, http:\/\/pax.grsecurity.net\/docs\/aslr.txt."},{"key":"R24","unstructured":"Control-flow-integrity-cfi-clang, https:\/\/www.redhat.com\/en\/blog\/fighting-exploits-control-flow-integrity-cfi-clang."},{"key":"R25","doi-asserted-by":"crossref","unstructured":"Fuzzing IW. SAGE: Whitebox Fuzzing for Security Testing. SAGE 2012; 10: 1.","DOI":"10.1145\/2090147.2094081"},{"key":"R26","first-page":"1","volume":"16","author":"Stephens","year":"2016","journal-title":"NDSS"},{"key":"R27","unstructured":"Yun I, Lee S and Xu M et al. QSYM: A practical concolic execution engine tailored for hybrid fuzzing. In: 27th USENIX Security Symposium (USENIX Security 18), 2018, 745\u2013761."},{"key":"R28","first-page":"209","volume":"8","author":"Cadar","year":"2008","journal-title":"OSDI"},{"key":"R29","doi-asserted-by":"crossref","unstructured":"Cha SK, Avgerinos T and Rebert A et al. Unleashing mayhem on binary code. In: 2012 IEEE Symposium on Security and Privacy, IEEE, 2012, 380\u2013394.","DOI":"10.1109\/SP.2012.31"},{"key":"R30","doi-asserted-by":"crossref","unstructured":"Shoshitaishvili Y, Wang R and Salls C et al. Sok:(state of) the art of war: Offensive techniques in binary analysis. In: 2016 IEEE symposium on security and privacy (SP), IEEE, 2016, 138\u2013157.","DOI":"10.1109\/SP.2016.17"},{"key":"R31","unstructured":"SSH CRC-32. Compensation Attack Detector Vulnerability. http:\/\/www.securityfocus.com\/bid\/2347\/"},{"key":"R32","unstructured":"Eniser HF, Zhang H and David C et al. Towards Translating Real-World Code with LLMs: A Study of Translating to Rust, 2024, ArXiv preprint [arXiv: https:\/\/arxiv.org\/abs\/2405.11514]."},{"key":"R33","unstructured":"Klabnik S and Nichols C. The Rust Programming Language, No Starch Press, 2018, https:\/\/doc.rust-lang.org\/book\/"},{"key":"R34","doi-asserted-by":"crossref","first-page":"159","DOI":"10.1016\/0167-6423(94)00030-I","volume":"24","author":"Scholefield","year":"1995","journal-title":"Sci Comput Program"},{"key":"R35","doi-asserted-by":"crossref","unstructured":"Gong Y, Chen M and Song L et al. Study on the classification model of lock mechanism in operating system. In: 2022 IEEE 2nd International Conference on Power, Electronics and Computer Applications (ICPECA), IEEE, 2022, 857\u2013861.","DOI":"10.1109\/ICPECA53709.2022.9718877"},{"key":"R36","doi-asserted-by":"crossref","unstructured":"Emre M, Schroeder R and Dewey K et al. Translating C to safer Rust. In: Proceedings of the ACM on Programming Languages, 2021, 5(OOPSLA), 1\u201329.","DOI":"10.1145\/3485498"},{"key":"R37","doi-asserted-by":"crossref","unstructured":"Guo J, Jiang Y and Zhao Y et al. Dlfuzz: Differential fuzzing testing of deep learning systems. In: Proceedings of the 2018 26th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, 2018, 739\u2013743.","DOI":"10.1145\/3236024.3264835"},{"key":"R38","doi-asserted-by":"crossref","unstructured":"Nilizadeh S, Noller Y and Pasareanu CS. Diffuzz: differential fuzzing for side-channel analysis. In: 2019 IEEE\/ACM 41st International Conference on Software Engineering (ICSE), IEEE, 2019, 176\u2013187.","DOI":"10.1109\/ICSE.2019.00034"},{"key":"R39","doi-asserted-by":"crossref","unstructured":"Philippsen M and Haumacher B. More efficient object serialization. In: International Parallel Processing Symposium, Berlin, Heidelberg: Springer Berlin Heidelberg, 1999, 718\u2013732.","DOI":"10.1007\/BFb0097962"},{"key":"R40","unstructured":"Citrus Developers. [n.d.]. Citrus \/ Citrus, https:\/\/gitlab.com\/citrus-rs\/citrus"},{"key":"R41","unstructured":"Sharp J. jameysharp\/corrode, 2020, https:\/\/github.com\/jameysharp\/corrode, Original-date: 2016-05-05T21:12:52Z."},{"key":"R42","unstructured":"Immunant Inc. immunant\/c2rust, 2020b, https:\/\/github.com\/immunant\/c2rust, Original-date: 2018-04-20T00:05:50Z."},{"key":"R43","doi-asserted-by":"crossref","unstructured":"Kuznetzov V, Szekeres L, Payer M, Candea G, Sekar R and Song D. Code-pointer integrity. In: The Continuing Arms Race: Code-Reuse Attacks and Defenses, 2018, pp. 81\u2013116.","DOI":"10.1145\/3129743.3129748"},{"key":"R44","unstructured":"Liljestrand H, Nyman T and Wang K et al. PAC it up: towards pointer integrity using ARM pointer authentication. In: USENIX Security Symposium, ACM, 2019."},{"key":"R45","unstructured":"Nagarakatte S, Martin MMK and Zdancewic S. Everything you want to know about pointer-based checking. In: Proceedings of 1st Summit on Advances in Programming Languages (SNAPL 2015), Schloss Dagstuhl-Leibniz-Zentrum fuerInformatik, 2015."},{"key":"R46","doi-asserted-by":"crossref","unstructured":"Duck GJ, Yap RHC and Cavallaro L. Stack Bounds Protection with Low Fat Pointers. In: Proceedings of NDSS, Vol. 17, 2017, 1\u201315.","DOI":"10.14722\/ndss.2017.23287"},{"key":"R47","doi-asserted-by":"crossref","unstructured":"Duck GJ and Yap RHC. Heap bounds protection with low fat pointers. In: Proceedings of the 25th International Conference on Compiler Construction, 2016, 132\u2013142","DOI":"10.1145\/2892208.2892212"},{"key":"R48","first-page":"1","volume":"27","author":"Feng","year":"2021","journal-title":"Design Autom. Electronic Syst. (TODAES)"},{"key":"R49","doi-asserted-by":"crossref","first-page":"365","DOI":"10.1016\/j.cose.2019.04.002","volume":"84","author":"Lu","year":"2019","journal-title":"Comput Secur"},{"key":"R50","doi-asserted-by":"crossref","unstructured":"Nagarakatte S, Zhao J and Martin MMK et al. SoftBound: Highly compatible and complete spatial memory safety for C. In: Proceedings of the 30th ACM SIGPLAN Conference on Programming Language Design and Implementation, 2009, 245\u2013258.","DOI":"10.1145\/1542476.1542504"}],"container-title":["Security and Safety"],"original-title":[],"link":[{"URL":"https:\/\/sands.edpsciences.org\/10.1051\/sands\/2024015\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,25]],"date-time":"2025-02-25T08:52:57Z","timestamp":1740473577000},"score":1,"resource":{"primary":{"URL":"https:\/\/sands.edpsciences.org\/10.1051\/sands\/2024015"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":50,"alternative-id":["sands20240008"],"URL":"https:\/\/doi.org\/10.1051\/sands\/2024015","relation":{},"ISSN":["2826-1275"],"issn-type":[{"type":"electronic","value":"2826-1275"}],"subject":[],"published":{"date-parts":[[2025]]}}}