{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T23:29:37Z","timestamp":1740180577771,"version":"3.37.3"},"reference-count":59,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2021,9,16]],"date-time":"2021-09-16T00:00:00Z","timestamp":1631750400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,9,16]],"date-time":"2021-09-16T00:00:00Z","timestamp":1631750400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100000183","name":"Army Research Office","doi-asserted-by":"crossref","award":["W911NF-13-1-0421"],"award-info":[{"award-number":["W911NF-13-1-0421"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1814679","CNS-2019340"],"award-info":[{"award-number":["CNS-1814679","CNS-2019340"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"published-print":{"date-parts":[[2021,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Performance\/security trade-off is widely noticed in CFI research, however, we observe that not every CFI scheme is subject to the trade-off. Motivated by the key observation, we ask three questions: \u278a does trade-off really exist in different CFI schemes? \u278b if trade-off do exist, how do previous works comply with it? \u278c how can it inspire future research? Although the three questions probably cannot be directly answered, they are inspiring. We find that a deeper understanding of the nature of the trade-off will help answer the three questions. Accordingly, we proposed the<jats:sc>GPT<\/jats:sc>conjecture to pinpoint the trade-off in designing CFI schemes, which says that at most two out of three properties (fine granularity, acceptable performance, and preventive protection) could be achieved.<\/jats:p>","DOI":"10.1186\/s42400-021-00098-2","type":"journal-article","created":{"date-parts":[[2021,9,16]],"date-time":"2021-09-16T03:30:48Z","timestamp":1631763048000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Position paper: GPT conjecture: understanding the trade-offs between granularity, performance and timeliness in control-flow integrity"],"prefix":"10.1186","volume":"4","author":[{"given":"Zhilong","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peng","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,9,16]]},"reference":[{"issue":"1","key":"98_CR1","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1145\/1609956.1609960","volume":"13","author":"M Abadi","year":"2009","unstructured":"Abadi M, Budiu M, Erlingsson \u00da, Ligatti J (2009) Control-flow integrity principles, implementations, and applications. ACM Trans Inf Syst Secur (TISSEC) 13(1):4","journal-title":"ACM Trans Inf Syst Secur (TISSEC)"},{"key":"98_CR2","doi-asserted-by":"crossref","unstructured":"Abadi M, Budiu M, Erlingsson \u00da, Ligatti J (2005) Control-flow integrity. In: Proceedings of the 12th ACM conference on computer and communications security, CCS \u201905, New York, NY, USA, ACM, pp 340\u2013353","DOI":"10.1145\/1102120.1102165"},{"key":"98_CR3","doi-asserted-by":"crossref","unstructured":"Abbasi A, Holz T, Zambon E, Etalle S (2017) ECFI: asynchronous control flow integrity for programmable logic controllers. In: Proceedings of the 33rd annual computer security applications conference, ACSAC 2017, New York, NY, USA, ACM, pp 437\u2013448","DOI":"10.1145\/3134600.3134618"},{"key":"98_CR4","doi-asserted-by":"crossref","unstructured":"Allen FE (1970) Control flow analysis. In: Proceedings of a symposium on compiler optimization, New York, NY, USA, ACM, pp 1\u201319","DOI":"10.1145\/800028.808479"},{"key":"98_CR5","unstructured":"Andersen S, Abella V (2004) Data execution prevention. Changes to functionality in Microsoft Windows XP Service Pack 2, Part 3. Memory protection technologies"},{"key":"98_CR6","doi-asserted-by":"crossref","unstructured":"Bounov D, Kici RG\u00f6, Lerner S (2016) Protecting C++ dynamic dispatch through VTable interleaving. In: The network and distributed system security symposium (NDSS)","DOI":"10.14722\/ndss.2016.23421"},{"issue":"1","key":"98_CR7","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1145\/3054924","volume":"50","author":"N Burow","year":"2017","unstructured":"Burow N, Carr SA, Nash J, Larsen P, Franz M, Brunthaler S, Payer M (2017) Control-flow integrity: precision, security, and performance. ACM Comput Surv 50(1):16","journal-title":"ACM Comput Surv"},{"key":"98_CR8","doi-asserted-by":"crossref","unstructured":"Burow N, McKee D, Carr SA, Payer M (2018) CfIXX: object type integrity for C++ virtual dispatch. In: Proceedings of network and distributed system security symposium (NDSS). https:\/\/hexhive.epfl.ch\/publications\/files\/18NDSS.pdf","DOI":"10.14722\/ndss.2018.23279"},{"key":"98_CR9","doi-asserted-by":"crossref","unstructured":"Cheng Y, Zhou Z, Miao Y, Ding X, Deng RH (2014) ROPecker: a generic and practical approach for defending against ROP attack. In: Symposium on network and distributed system security (NDSS). Internet Society","DOI":"10.14722\/ndss.2014.23156"},{"key":"98_CR10","unstructured":"Chen S, Xu J, Sezer EC, Gauriar P, Iyer RK (2005) Non-control-data attacks are realistic threats. In: USENIX security symposium, vol 5"},{"key":"98_CR11","unstructured":"Cowan C, Calton P, Maier D, Walpole J, Bakke P, Beattie S, Grier A, Wagle P, Zhang Q, Hinton H (1998) Stackguard: automatic adaptive detection oand prevention of buffer-overflow attacks. In: USENIX security symposium. San Antonio, TX"},{"key":"98_CR12","doi-asserted-by":"crossref","unstructured":"Criswell J, Dautenhahn N, Adve V (2014) KCoFI: complete control-flow integrity for commodity operating system kernels. In: 2014 IEEE symposium on security and privacy, pp 292\u2013307","DOI":"10.1109\/SP.2014.26"},{"key":"98_CR13","doi-asserted-by":"crossref","unstructured":"Dang THY, Maniatis P, Wagner D (2015) The performance cost of shadow stacks and stack canaries. In: Proceedings of the 10th ACM symposium on information, computer and communications security (ASIACCS 15), New York, NY, USA, ACM, pp 555\u2013566","DOI":"10.1145\/2714576.2714635"},{"key":"98_CR14","unstructured":"Ding R, Qian C, Song C, Harris B, Kim T, Lee W (2017) Efficient protection of path-sensitive control security. In: 26th USENIX security symposium (USENIX security 17), Vancouver, BC, USENIX Association, pp 131\u2013148"},{"key":"98_CR15","unstructured":"Erickson J (2008) Hacking: the art of exploitation"},{"key":"98_CR16","unstructured":"Fratri\u0107 I (2012) ROPGuard: runtime prevention of return-oriented programming attacks. Technical report"},{"key":"98_CR17","doi-asserted-by":"crossref","unstructured":"Ge X, Cui W, Jaeger T (2017) GRIFFIN: guarding control flows using intel processor trace. In: Proceedings of the twenty-second international conference on architectural support for programming languages and operating systems (ASPLOS 17), New York, NY, USA, ACM, pp 585\u2013598","DOI":"10.1145\/3037697.3037716"},{"key":"98_CR18","doi-asserted-by":"crossref","unstructured":"G\u00f6ktas E, Athanasopoulos E, Bos H, Portokalidis G (2014) Out of control: overcoming control-flow integrity. In: 2014 IEEE symposium on security and privacy (S&P). IEEE","DOI":"10.1109\/SP.2014.43"},{"issue":"3","key":"98_CR19","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1145\/1412700.1412710","volume":"39","author":"O Goldreich","year":"2008","unstructured":"Goldreich O (2008) Computational complexity: a conceptual perspective. SIGACT News 39(3):35\u201339","journal-title":"SIGACT News"},{"key":"98_CR20","doi-asserted-by":"crossref","unstructured":"Hind M (2001) Pointer analysis: Haven\u2019T we solved this problem yet? In: Proceedings of the 2001 ACM SIGPLAN-SIGSOFT workshop on program analysis for software tools and engineering, PASTE \u201901, New York, NY, USA, ACM, pp 54\u201361","DOI":"10.1145\/379605.379665"},{"issue":"1","key":"98_CR21","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/239912.239913","volume":"19","author":"S Horwitz","year":"1997","unstructured":"Horwitz S (1997) Precise flow-insensitive may-alias analysis is NP-hard. ACM Trans Program Lang Syst 19(1):1\u20136","journal-title":"ACM Trans Program Lang Syst"},{"key":"98_CR22","doi-asserted-by":"crossref","unstructured":"Hu H, Qian C, Yagemann C, Chung SPH, Harris WR, Kim T, Lee W (2018) Enforcing unique code target property for control-flow integrity. In: Proceedings of the 2018 ACM SIGSAC conference on computer and communications security. ACM, pp 1470\u20131486","DOI":"10.1145\/3243734.3243797"},{"key":"98_CR23","doi-asserted-by":"crossref","unstructured":"Jang D, Tatlock Z, Lerner S (2014) SafeDispatch: securing C++ virtual calls from memory corruption attacks. In: the Network and distributed system security symposium (NDSS)","DOI":"10.14722\/ndss.2014.23287"},{"key":"98_CR24","doi-asserted-by":"crossref","unstructured":"Khedker U, Sanyal A, Sathe B (2017) Theory and practice, data flow analysis","DOI":"10.1201\/9780849332517"},{"key":"98_CR25","unstructured":"LLVM\u2014control flow integrity (2015)"},{"key":"98_CR26","unstructured":"Lucas D, Sadeghi A-R, Lehmann D, Monrose F (2014) Stitching the gadgets: on the ineffectiveness of coarse-grained control-flow integrity protection. In: 23rd USENIX security symposium (USENIX Security 14). USENIX"},{"key":"98_CR27","doi-asserted-by":"crossref","unstructured":"Mashtizadeh AJ, Bittau A, Boneh D, Mazi\u00e8res D (2015) CCFI: cryptographically enforced control flow integrity. In: Proceedings of the 22nd ACM SIGSAC conference on computer and communications security. ACM, pp 941\u2013951","DOI":"10.1145\/2810103.2813676"},{"key":"98_CR28","doi-asserted-by":"crossref","unstructured":"Mastrolilli M (2021) The complexity of the ideal membership problem for constrained problems over the Boolean domain","DOI":"10.1145\/3449350"},{"key":"98_CR29","unstructured":"Microsoft. Visual Studio 2015\u2014compiler options\u2014enable control flow guard (2015)"},{"key":"98_CR30","doi-asserted-by":"crossref","unstructured":"Mohan V, Larsen P, Brunthaler S, Hamlen KW, Franz M (2015) Opaque control-flow integrity. In: The network and distributed system security symposium (NDSS), vol 26, pp 27\u201330","DOI":"10.14722\/ndss.2015.23271"},{"key":"98_CR31","doi-asserted-by":"crossref","unstructured":"Muntean P, Fischer M, Tan G, Lin Z, Grossklags J, Eckert C (2018) $$\\tau$$ CFI: type-assisted control flow integrity for x86-64 binaries. In: International symposium on research in attacks, intrusions, and defenses. Springer, pp 423\u2013444","DOI":"10.1007\/978-3-030-00470-5_20"},{"key":"98_CR32","unstructured":"Nagarakatte SG (2012) Practical low-overhead enforcement of memory safety for C programs"},{"key":"98_CR33","unstructured":"Newsome J, Song DX (2005) Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In: The network and distributed system security symposium (NDSS). Citeseer, vol 5, pp 3\u20134"},{"key":"98_CR34","doi-asserted-by":"crossref","unstructured":"Niu B, Tan G (2014) Modular control-flow integrity. In: Proceedings of the 35th ACM SIGPLAN conference on programming language design and implementation (PLDI 14), New York, NY, USA. ACM, pp 577\u2013587","DOI":"10.1145\/2594291.2594295"},{"key":"98_CR35","doi-asserted-by":"crossref","unstructured":"Niu B, Tan G (2015) Per-input control-flow integrity. In: Proceedings of the 22nd ACM SIGSAC conference on computer and communications security, CCS \u201915, New York, NY, USA, ACM, pp 914\u2013926","DOI":"10.1145\/2810103.2813644"},{"key":"98_CR36","unstructured":"Pappas V, Polychronakis M, Keromytis AD (2013) Transparent ROP exploit mitigation using indirect branch tracing. In: Proceeding of the 22nd USENIX security symposium (USENIX security 13), pp 447\u2013462"},{"key":"98_CR37","unstructured":"Patil H, Fischer CN (1995) Efficient run-time monitoring using shadow processing. In: Proceeding of automated and algorithmic debugging (AADEBUG), vol 95, pp 1\u201314"},{"key":"98_CR38","doi-asserted-by":"crossref","unstructured":"Payer M, Barresi A, Gross TR (2015) Fine-grained control-flow integrity through binary hardening. In: International conference on detection of intrusions and malware, and vulnerability assessment. Springer, pp 144\u2013164","DOI":"10.1007\/978-3-319-20550-2_8"},{"issue":"8","key":"98_CR39","doi-asserted-by":"publisher","first-page":"1044","DOI":"10.1364\/OL.31.001044","volume":"31","author":"X Peng","year":"2006","unstructured":"Peng X, Zhang P, Wei H, Bin Yu (2006) Known-plaintext attack on optical encryption based on double random phase keys. Opt Lett 31(8):1044\u20131046","journal-title":"Opt Lett"},{"key":"98_CR40","doi-asserted-by":"crossref","unstructured":"Prakash A, Hu X, Yin H (2015) vfGuard: strict protection for virtual function calls in COTS C++ binaries. In: Symposium on network and distributed system security (NDSS)","DOI":"10.14722\/ndss.2015.23297"},{"key":"98_CR41","doi-asserted-by":"crossref","unstructured":"Santana OJ, Falc\u00f3n A, Fern\u00e1ndez E, Medina P, Ram\u00edrez A, Valero M (2002) A comprehensive analysis of indirect branch prediction. In: Hans PZ, Kazuki J, Mitsuhisa S, Yoshiki S, Masaaki S (eds) High performance computing. Springer, Berlin, pp 133\u2013145","DOI":"10.1007\/3-540-47847-7_13"},{"key":"98_CR42","doi-asserted-by":"crossref","unstructured":"Shacham H et al (2007) The geometry of innocent flesh on the bone: return-into-libc without function calls (on the x86). In: ACM conference on computer and communications security. New York, pp 552\u2013561","DOI":"10.1145\/1315245.1315313"},{"key":"98_CR43","doi-asserted-by":"crossref","unstructured":"Shacham H, Matthew P, Ben P, Eu-Jin G, Nagendra M, Dan B (2004) On the effectiveness of address-space randomization. In: Proceedings of the 11th ACM conference on computer and communications security. ACM","DOI":"10.1145\/1030083.1030124"},{"key":"98_CR44","unstructured":"SPEC CPU 2006 system requirements. https:\/\/www.spec.org\/cpu2006"},{"key":"98_CR45","unstructured":"Starr A, Abella V (2012) The BlueHat prize contest official rules"},{"key":"98_CR46","doi-asserted-by":"crossref","unstructured":"Szekeres L, Payer M, Wei T, Song DS (2013) Sok: eternal war in memory. In: 2013 IEEE symposium on security and privacy (S&P). IEEE, pp 48\u201362","DOI":"10.1109\/SP.2013.13"},{"key":"98_CR47","unstructured":"Tice C, Roeder T, Collingbourne P, Checkoway S, Erlingsson \u00da, Lozano L, Pike G (2014) Enforcing forward-edge control-flow integrity in GCC & LLVM. In: 23rd USENIX security symposium (USENIX security 14), pp 941\u2013955"},{"key":"98_CR48","doi-asserted-by":"crossref","unstructured":"Victor Van\u00a0der V, Andriesse D, G\u00f6kta\u015f E, Gras B, Sambuc L, Slowinska A, Bos H, Giuffrida C (2015) Practical context-sensitive CFI. In: Proceedings of the 22nd ACM SIGSAC conference on computer and communications security. ACM, pp 927\u2013940","DOI":"10.1145\/2810103.2813673"},{"key":"98_CR49","doi-asserted-by":"crossref","unstructured":"Wartell R, Mohan V, Hamlen KW, Lin Z (2012) Securing untrusted code via compiler-agnostic binary rewriting. In: Proceedings of the 28th annual computer security applications conference. ACM, pp 299\u2013308","DOI":"10.1145\/2420950.2420995"},{"key":"98_CR50","doi-asserted-by":"crossref","unstructured":"Woeginger GJ (2004) Space and time complexity of exact algorithms: some open problems. In: Rod D, Michael F, Frank D (eds) Parameterized and exact computation. Springer, Berlin, pp 281\u2013290","DOI":"10.1007\/978-3-540-28639-4_25"},{"key":"98_CR51","unstructured":"Wojtczuk R (2001) The advanced return-into-Libc exploits: PaX case study. Phrack Magazine"},{"key":"98_CR52","unstructured":"Xia Y, Liu Y, Chen H, Zang B (2012) CFIMon: detecting violation of control flow integrity using performance counters. In: IEEE\/IFIP international conference on dependable systems and networks (DSN 2012). IEEE, pp 1\u201312"},{"key":"98_CR53","unstructured":"Xiaoyang X, Ghaffarinia M, Wang W, Hamlen KW, Lin Z (2019) CONFIRM: evaluating compatibility and relevance of control-flow integrity protections for modern software. In: 28th USENIX security symposium (USENIX Security 19), Santa Clara, CA, August 2019. USENIX Association, Santa Clara, CA, August, pp 1805\u20131821"},{"key":"98_CR54","doi-asserted-by":"crossref","unstructured":"Yee B, Sehr D, Dardyk G, Chen JB, Muth R, Ormandy T, Okasaka S, Narula N, Fullagar N (2009) Native client: a sandbox for portable, untrusted x86 native code. In: 2009 30th IEEE symposium on security and privacy (S&P), pp 79\u201393","DOI":"10.1109\/SP.2009.25"},{"issue":"1","key":"98_CR55","doi-asserted-by":"publisher","first-page":"458","DOI":"10.1109\/JIOT.2018.2866164","volume":"6","author":"J Zhang","year":"2019","unstructured":"Zhang J, Qi B, Qin Z, Qu G (2019) HCIC: hardware-assisted control-flow integrity checking. IEEE Internet Things J 6(1):458\u2013471","journal-title":"IEEE Internet Things J"},{"key":"98_CR56","doi-asserted-by":"crossref","unstructured":"Zhang J, Hou R, Fan J, Liu K, Zhang L, McKee SA (2017) RAGuard: a hardware based mechanism for backward-edge control-flow integrity. In: Proceedings of the computing frontiers conference, CF\u201917, New York, NY, USA, ACM, pp 27\u201334","DOI":"10.1145\/3075564.3075570"},{"key":"98_CR57","unstructured":"Zhang M, Sekar R (2013) Control flow integrity for COTS binaries. In: Proceeding of the 22nd USENIX security symposium (USENIX security 13), pp 337\u2013352"},{"key":"98_CR58","doi-asserted-by":"crossref","unstructured":"Zhang C, Wei T, Chen Z, Duan L, Szekeres L, McCamant S, Song D, Zou W (2013) Practical control flow ontegrity and randomization for binary executables. In: 2013 IEEE symposium on security and privacy (S&P). IEEE, pp 559\u2013573","DOI":"10.1109\/SP.2013.44"},{"key":"98_CR59","unstructured":"Zhi W, Xuxian J (2010) HyperSafe: a lightweight approach to provide lifetime hypervisor control-flow integrity. In: 2010 IEEE symposium on security and privacy, pp 380\u2013395"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00098-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-021-00098-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00098-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,9]],"date-time":"2023-01-09T10:12:20Z","timestamp":1673259140000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-021-00098-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,16]]},"references-count":59,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,12]]}},"alternative-id":["98"],"URL":"https:\/\/doi.org\/10.1186\/s42400-021-00098-2","relation":{},"ISSN":["2523-3246"],"issn-type":[{"type":"electronic","value":"2523-3246"}],"subject":[],"published":{"date-parts":[[2021,9,16]]},"assertion":[{"value":"14 May 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 August 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 September 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"33"}}