{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T19:32:22Z","timestamp":1760297542842,"version":"3.41.0"},"reference-count":16,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2005,3,1]],"date-time":"2005-03-01T00:00:00Z","timestamp":1109635200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGARCH Comput. Archit. News"],"published-print":{"date-parts":[[2005,3]]},"abstract":"<jats:p>Stack-smashing by buffer overflow is a common tactic used by viruses and worms to crash or hijack systems. Exploiting a bounds-unchecked copy into a stack buffer, an attacker can---by supplying a specially-crafted and unexpectedly long input---overwrite a stored return address and trigger the execution of code of her choosing. In this paper, we propose to protect code from this common form of attack using dynamic instruction stream editing (DISE), a previously proposed hardware mechanism that implements binary rewriting in a transparent, efficient, and convenient way by rewriting the dynamic instruction stream rather than the static executable. Simply, we define productions (rewriting rules) that instrument program calls and returns to maintain and verify a \"shadow\" stack of return addresses in a protected region of memory. When invalid return addresses are detected, the application is terminated.The DISE implementation resembles previous software schemes like StackGuard and the Return Address Defender (RAD), but it can operate without source code and in dynamically-linked libraries and dynamically-generated code. It also has natural facilities for protecting the shadow stack, which provides little security if it itself is vulnerable. Finally, unlike software instrumentation, DISE checks---which are inserted by the processor at runtime---cannot be bypassed or subverted.<\/jats:p>","DOI":"10.1145\/1055626.1055636","type":"journal-article","created":{"date-parts":[[2005,11,7]],"date-time":"2005-11-07T19:28:32Z","timestamp":1131391712000},"page":"65-72","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":22,"title":["Using DISE to protect return addresses from attack"],"prefix":"10.1145","volume":"33","author":[{"given":"Marc L.","family":"Corliss","sequence":"first","affiliation":[{"name":"University of Pennsylvania, Philadelphia, PA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"E. Christopher","family":"Lewis","sequence":"additional","affiliation":[{"name":"University of Pennsylvania, Philadelphia, PA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Amir","family":"Roth","sequence":"additional","affiliation":[{"name":"University of Pennsylvania, Philadelphia, PA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2005,3]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Nov.","author":"One Aleph","year":"1996","unstructured":"Aleph One . Smashing the stack for fun and profit. Phrack, 7(49) , Nov. 1996 . Aleph One. Smashing the stack for fun and profit. Phrack, 7(49), Nov. 1996."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.5555\/1267724.1267745"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.5555\/876878.879316"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/859618.859660"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/780732.780765"},{"key":"e_1_2_1_9_1","first-page":"63","volume-title":"Proc. of 7th USENIX Security Conference","author":"Cowan C.","year":"1998","unstructured":"C. Cowan , C. Pu , D. Maier , J. Walpole , P. Bakke , S. Beattie , A. Grier , P. Wagle , Q. Zhang , and H. Hinton . StackGuard: Automatic adaptive detection and prevention buffer overflow attacks . In Proc. of 7th USENIX Security Conference , pages 63 -- 78 , Jan. 1998 . C. Cowan, C. Pu, D. Maier, J. Walpole, P. Bakke, S. Beattie, A. Grier, P. Wagle, Q. Zhang, and H. Hinton. StackGuard: Automatic adaptive detection and prevention buffer overflow attacks. In Proc. of 7th USENIX Security Conference, pages 63--78, Jan. 1998."},{"key":"e_1_2_1_10_1","volume-title":"Nov.","author":"Diefendorf K.","year":"1998","unstructured":"K. Diefendorf . K7 challenges Intel. Microprocessor Report, 12(14) , Nov. 1998 . K. Diefendorf. K7 challenges Intel. Microprocessor Report, 12(14), Nov. 1998."},{"key":"e_1_2_1_11_1","first-page":"55","volume-title":"Proc. of the 10th USENIX Security Symposium","author":"Frantzen M.","year":"2001","unstructured":"M. Frantzen and M. Shuey . StackGhost: Hardware facilitated stack protection . In Proc. of the 10th USENIX Security Symposium , pages 55 -- 66 , Aug. 2001 . M. Frantzen and M. Shuey. StackGhost: Hardware facilitated stack protection. In Proc. of the 10th USENIX Security Symposium, pages 55--66, Aug. 2001."},{"key":"e_1_2_1_12_1","volume-title":"Aug.","author":"Glaskowsky P.","year":"2000","unstructured":"P. Glaskowsky . Pentium 4 (partially) previewed. Microprocessor Report, 14(8) , Aug. 2000 . P. Glaskowsky. Pentium 4 (partially) previewed. Microprocessor Report, 14(8), Aug. 2000."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.5555\/1128020.1128563"},{"key":"e_1_2_1_14_1","first-page":"13","volume-title":"Proc. of the Int. Workshop on Automatic Debugging","author":"Jones R.","year":"1997","unstructured":"R. Jones and P. Kelly . Backwards-compatible bounds checking for arrays and pointers in C programs . In Proc. of the Int. Workshop on Automatic Debugging , pages 13 -- 26 , May 1997 . R. Jones and P. Kelly. Backwards-compatible bounds checking for arrays and pointers in C programs. In Proc. of the Int. Workshop on Automatic Debugging, pages 13--26, May 1997."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2004.36"},{"key":"e_1_2_1_16_1","volume-title":"Proc. of the 11th Network and Distributed Systems Security Symposium","author":"Ruwase O.","year":"2004","unstructured":"O. Ruwase and M. S. Lam . A practical dynamic buffer overflow detector . In Proc. of the 11th Network and Distributed Systems Security Symposium , Feb. 2004 . O. Ruwase and M. S. Lam. A practical dynamic buffer overflow detector. In Proc. of the 11th Network and Distributed Systems Security Symposium, Feb. 2004."},{"key":"e_1_2_1_17_1","unstructured":"Solar Designer. Linux kernel patch from the openwall project. http:\/\/www.openwall.com\/linux\/ 2004.  Solar Designer. Linux kernel patch from the openwall project. http:\/\/www.openwall.com\/linux\/ 2004."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/168619.168635"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/1153923.1154543"}],"container-title":["ACM SIGARCH Computer Architecture News"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1055626.1055636","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1055626.1055636","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:31:27Z","timestamp":1750264287000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1055626.1055636"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005,3]]},"references-count":16,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2005,3]]}},"alternative-id":["10.1145\/1055626.1055636"],"URL":"https:\/\/doi.org\/10.1145\/1055626.1055636","relation":{},"ISSN":["0163-5964"],"issn-type":[{"type":"print","value":"0163-5964"}],"subject":[],"published":{"date-parts":[[2005,3]]},"assertion":[{"value":"2005-03-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}