{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T11:04:12Z","timestamp":1777806252135,"version":"3.51.4"},"reference-count":74,"publisher":"SAGE Publications","issue":"3","license":[{"start":{"date-parts":[[2023,11,24]],"date-time":"2023-11-24T00:00:00Z","timestamp":1700784000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2024,6,17]]},"abstract":"<jats:p>By developing a Turing-complete non-control data attack to bypass existing defenses against control flow attacks, Data-Oriented Programming (DOP) has gained significant attention from researchers in recent years. While several defense techniques have been proposed to mitigate DOP attacks, they often introduce substantial overhead due to the blind protection of a large range of data objects. To address this issue, we focus on selecting and protecting the specific target data that are of interest to DOP attackers, rather than securing the entire non-control data in the program. In this regard, we perform static analysis on 20 real-world applications and identify the target data, verifying that they constitute only a small percentage of the overall program, averaging around 3%. Additionally, we propose a semi-automated tool to analyze how to chain operations on the target data in these 20 applications to achieve Turing-complete attacks. Furthermore, we introduce DSLR-: a low-overhead Data Structure Layout Randomization (DSLR) method, which modifies the existing DSLR technique to only randomize the selected target data for DOP. Experimental results demonstrate that DSLR- effectively mitigates DOP attacks, reducing performance overhead by 71.2% and memory overhead by 82.5% compared to the original DSLR technique.<\/jats:p>","DOI":"10.3233\/jcs-230053","type":"journal-article","created":{"date-parts":[[2023,11,24]],"date-time":"2023-11-24T12:41:53Z","timestamp":1700829713000},"page":"221-246","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":0,"title":["DSLR\u2013: A low-overhead data structure layout randomization for defending data-oriented programming"],"prefix":"10.1177","volume":"32","author":[{"given":"Jin","family":"Wei","sequence":"first","affiliation":[{"name":"School of Computer Science, Fudan University, Shanghai, China"},{"name":"Institute of BigData, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ping","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of BigData, Fudan University, Shanghai, China"},{"name":"Purple Mountain Laboratories, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2023,11,24]]},"reference":[{"key":"ref001","unstructured":"P.\u00a0Akritidis, M.\u00a0Costa, M.\u00a0Castro and S.\u00a0Hand, Baggy bounds checking: An efficient and backwards-compatible defense against out-of-bounds errors, in: USENIX Security Symposium, Vol.\u00a010, 2009."},{"key":"ref002","unstructured":"Aspell, http:\/\/aspell.net."},{"key":"ref003","doi-asserted-by":"crossref","unstructured":"S.\u00a0Bhatkar and R.\u00a0Sekar, Data space randomization, in: Detection of Intrusions and Malware, and Vulnerability Assessment: 5th International Conference, DIMVA 2008, Paris, France, July 10\u201311, 2008, Proceedings 5, Springer, 2008, pp.\u00a01\u201322.","DOI":"10.1007\/978-3-540-70542-0_1"},{"key":"ref004","doi-asserted-by":"publisher","DOI":"10.1145\/1966913.1966919"},{"key":"ref005","unstructured":"BOPC, https:\/\/github.com\/HexHive\/BOPC."},{"key":"ref006","doi-asserted-by":"crossref","unstructured":"J.\u00a0Caballero, G.\u00a0Grieco, M.\u00a0Marron and A.\u00a0Nappa, Undangle: Early detection of dangling pointers in use-after-free and double-free vulnerabilities, in: 2012 International Symposium on Software Testing and Analysis, 2012, pp.\u00a0133\u2013143.","DOI":"10.1145\/2338965.2336769"},{"key":"ref007","unstructured":"C.\u00a0Cadar, P.\u00a0Akritidis, M.\u00a0Costa, J.P.\u00a0Martin and M.\u00a0Castro, Data randomization, Technical Report TR-2008-120, Microsoft Research, 2008."},{"key":"ref008","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24174-6_4"},{"key":"ref009","unstructured":"S.\u00a0Chen, J.\u00a0Xu, E.C.\u00a0Sezer, P.\u00a0Gauriar and K.I.\u00a0Ravishankar, Non-control-data attacks are realistic threats, in: USENIX Security Symposium, Vol.\u00a05, 2005, p.\u00a0146."},{"key":"ref010","doi-asserted-by":"publisher","DOI":"10.1145\/3462699"},{"key":"ref011","unstructured":"Control-flow-integrity-cfi-clang, https:\/\/www.redhat.com\/en\/blog\/fighting-exploits-control-flow-integrity-cfi-clang."},{"key":"ref012","unstructured":"Curl, ttps:\/\/github.com\/curl\/."},{"key":"ref013","unstructured":"CVE Vulnerabilities, https:\/\/cve.mitre.org\/."},{"key":"ref014","unstructured":"CVE\u20132014\u20130333, https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2014-0333."},{"key":"ref015","unstructured":"CVE\u20132015\u20130205, https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2015-0205."},{"key":"ref016","unstructured":"W.A.\u00a0Dahl, L.\u00a0Erdodi and F.M.\u00a0Zennaro, Stack-based buffer overflow detection using recurrent neural networks, 2020, arXiv preprint arXiv:2012.15116."},{"key":"ref017","unstructured":"Dop Tool, https:\/\/huhong789.github.io\/advanced-DOP\/."},{"key":"ref018","doi-asserted-by":"publisher","DOI":"10.1145\/2892208.2892212"},{"key":"ref019","doi-asserted-by":"crossref","unstructured":"G.J.\u00a0Duck, R.H.C.\u00a0Yap and L.\u00a0Cavallaro, Stack bounds protection with low fat pointers, in: NDSS, Vol.\u00a017, 2017, pp.\u00a01\u201315.","DOI":"10.14722\/ndss.2017.23287"},{"key":"ref020","doi-asserted-by":"publisher","DOI":"10.1145\/3490176"},{"key":"ref021","unstructured":"Fuzzbenchmark, https:\/\/github.com\/google\/oss-fuzz\/tree\/master\/projects."},{"key":"ref022","doi-asserted-by":"publisher","DOI":"10.1007\/s11390-020-0525-z"},{"key":"ref023","unstructured":"H.\u00a0Hu, Z.L.\u00a0Chua, S.\u00a0Adrian, P.\u00a0Saxena and Z.\u00a0Liang, Automatic generation of data-oriented exploits, in: 24th {USENIX} Security Symposium ({USENIX} Security 15), 2015, pp.\u00a0177\u2013192."},{"key":"ref024","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243797"},{"key":"ref025","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.62"},{"key":"ref026","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3113512"},{"key":"ref027","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485376"},{"key":"ref028","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243739"},{"key":"ref029","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833650"},{"key":"ref030","unstructured":"R.W.\u00a0Jones and P.H.\u00a0Kelly, Backwards-compatible bounds checking for arrays and pointers in C programs, in: AADEBUG, Vol.\u00a097, 1997, pp.\u00a013\u201326."},{"key":"ref031","unstructured":"Jsoncpp, https:\/\/github.com\/open-source-parsers\/jsoncpp."},{"key":"ref032","doi-asserted-by":"crossref","unstructured":"M.\u00a0Khandaker, W.\u00a0Liu, A.\u00a0Naser, Z.\u00a0Wang and J.\u00a0Yang, in: Origin-Sensitive Control Flow Integrity., in: USENIX Security Symposium, 2019, pp.\u00a0195\u2013211.","DOI":"10.1109\/EuroSP.2019.00017"},{"key":"ref033","doi-asserted-by":"publisher","DOI":"10.1145\/360248.360252"},{"key":"ref034","doi-asserted-by":"publisher","DOI":"10.1145\/3129743.3129748"},{"key":"ref035","unstructured":"Libarchive, http:\/\/www.libarchive.org\/downloads."},{"key":"ref036","unstructured":"Libgit2, https:\/\/github.com\/libgit2."},{"key":"ref037","unstructured":"Libhevc, https:\/\/gitlab.com\/aosp1\/platform\/external\/libhevc\/."},{"key":"ref038","unstructured":"Libpcap, https:\/\/www.tcpdump.org\/release."},{"key":"ref039","unstructured":"Libpng, http:\/\/www.libpng.org\/pub\/png\/libpng.html."},{"key":"ref040","unstructured":"H.\u00a0Liljestrand, T.\u00a0Nyman, K.\u00a0Wang, C.C.\u00a0Perez, J.\u00a0Ekberg and N.\u00a0Asokan, in: PAC It up: Towards Pointer Integrity Using ARM Pointer Authentication., in: USENIX Security Symposium, 2019, pp.\u00a0177\u2013194."},{"key":"ref041","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02918-9_7"},{"key":"ref042","unstructured":"LLVM Pass, https:\/\/llvm.org\/docs\/WritingAnLLVMPass.html."},{"key":"ref043","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.04.002"},{"key":"ref044","unstructured":"Matio, https:\/\/github.com\/tbeu\/matio."},{"key":"ref045","unstructured":"S.\u00a0Nagarakatte, M.M.K.\u00a0Martin and S.\u00a0Zdancewic, Everything you want to know about pointer-based checking, in: 1st Summit on Advances in Programming Languages (SNAPL 2015), Schloss Dagstuhl-Leibniz-Zentrum Fuer Informatik, 2015."},{"key":"ref046","doi-asserted-by":"publisher","DOI":"10.1145\/1542476.1542504"},{"key":"ref047","doi-asserted-by":"publisher","DOI":"10.1145\/1065887.1065892"},{"key":"ref048","unstructured":"Nginx, http:\/\/nginx.org\/download."},{"key":"ref049","unstructured":"Openss, https:\/\/www.openssl.org\/source\/."},{"key":"ref050","unstructured":"Openssh, https:\/\/www.openssh.com\/."},{"key":"ref051","unstructured":"P. Team, PaX address space layout randomization, 2003, http:\/\/pax.grsecurity.net\/docs\/aslr.txt."},{"key":"ref052","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00082"},{"key":"ref053","unstructured":"PaX, Homepage of the PaX Team, 2001, http:\/\/pax.grsecurity.net."},{"key":"ref054","unstructured":"PHP, http:\/\/cn2.php.net\/get\/php-7.0.8.tar.gz\/from\/this\/mirror."},{"key":"ref055","doi-asserted-by":"publisher","DOI":"10.3390\/computers9020048"},{"key":"ref056","unstructured":"ProFTPD, http:\/\/www.proftpd.org\/."},{"key":"ref057","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384757"},{"key":"ref058","unstructured":"Randomize structure layout support for GCC, https:\/\/lwn.net\/Articles\/722293\/."},{"key":"ref059","unstructured":"Randomize structure layout support for LLVM, https:\/\/reviews.llvm.org\/D121556."},{"key":"ref060","doi-asserted-by":"publisher","DOI":"10.1145\/2133375.2133377"},{"key":"ref061","unstructured":"M.S.\u00a0Roodsari, E.\u00a0Nouri, F.\u00a0Sheikhshoaei, P.\u00a0Prinetto and Z.\u00a0Navabi, A Secure Canary-Based Hardware Approach Against ROP, 2022."},{"key":"ref062","unstructured":"O.\u00a0Ruwase and M.S.\u00a0Lam, A practical dynamic buffer overflow detector, in: NDSS, 2004, pp.\u00a0159\u2013169."},{"key":"ref063","unstructured":"Sqlite, https:\/\/www.sqlite.org."},{"key":"ref064","unstructured":"Standard Performance Evaluation Corporation, SPEC, http:\/\/www.spec.org\/osg\/cpu2006."},{"key":"ref065","unstructured":"Sudo, https:\/\/github.com\/sudo-project\/sudo\/releases."},{"key":"ref066","unstructured":"SVF, https:\/\/github.com\/SVF-tools\/SVF."},{"key":"ref067","doi-asserted-by":"crossref","unstructured":"M.\u00a0Tran, M.\u00a0Etheridge, T.\u00a0Bletsch, X.\u00a0Jiang, V.\u00a0Freeh and P.\u00a0Ning, On the expressiveness of return-into-libc attacks, in: Recent Advances in Intrusion Detection: 14th International Symposium, RAID 2011, Menlo Park, CA, USA, September 20\u201321, 2011, Proceedings 14, Springer, 2011, pp.\u00a0121\u2013141.","DOI":"10.1007\/978-3-642-23644-0_7"},{"key":"ref068","unstructured":"Vorbis, https:\/\/github.com\/xiph\/vorbis."},{"key":"ref069","doi-asserted-by":"crossref","unstructured":"H.\u00a0Wang, X.\u00a0Xie, Y.\u00a0Li, C.\u00a0Wen, Y.\u00a0Li, Y.\u00a0Liu, S.\u00a0Qin, H.\u00a0Chen and Y.\u00a0Sui, Typestate-guided fuzzer for discovering use-after-free vulnerabilities, in: Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering, 2020, pp.\u00a0999\u20131010.","DOI":"10.1145\/3377811.3380386"},{"key":"ref070","unstructured":"Whole-program-llvm, https:\/\/github.com\/travitch\/whole-program-llvm."},{"key":"ref071","unstructured":"WuFTPD, https:\/\/github.com\/pmarkowsky\/vulnerable-wu-ftpd-2.6.2."},{"key":"ref072","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00086"},{"key":"ref073","unstructured":"Zlib, https:\/\/github.com\/madler\/zlib."},{"key":"ref074","unstructured":"Zstd, https:\/\/github.com\/facebook\/zstd."}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-230053","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JCS-230053","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-230053","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:49Z","timestamp":1777495549000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-230053"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,24]]},"references-count":74,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2024,6,17]]}},"alternative-id":["10.3233\/JCS-230053"],"URL":"https:\/\/doi.org\/10.3233\/jcs-230053","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,11,24]]}}}