Matches in SemOpenAlex for { <https://semopenalex.org/work/W2564856904> ?p ?o ?g. }
- W2564856904 endingPage "13" @default.
- W2564856904 startingPage "1" @default.
- W2564856904 abstract "Address Space Layout Randomization (ASLR) is a widely-used technique that protects systems against a range of attacks. ASLR works by randomizing the offset of key program segments in virtual memory, making it difficult for an attacker to derive the addresses of specific code objects and consequently redirect the control flow to this code. In this paper, we develop an attack to derive kernel and user-level ASLR offset using a side-channel attack on the branch target buffer (BTB). Our attack exploits the observation that an adversary can create BTB collisions between the branch instructions of the attacker process and either the user-level victim process or on the kernel executing on its behalf. These collisions, in turn, can impact the timing of the attacker's code, allowing the attacker to identify the locations of known branch instructions in the address space of the victim process or the kernel. We demonstrate that our attack can reliably recover kernel ASLR in about 60 milliseconds when performed on a real Haswell processor running a recent version of Linux. Finally, we describe several possible protection mechanisms, both in software and in hardware." @default.
- W2564856904 created "2017-01-06" @default.
- W2564856904 creator A5059614371 @default.
- W2564856904 creator A5066100959 @default.
- W2564856904 creator A5087128492 @default.
- W2564856904 date "2016-10-15" @default.
- W2564856904 modified "2023-09-26" @default.
- W2564856904 title "Jump over ASLR: attacking branch predictors to bypass ASLR" @default.
- W2564856904 cites W1112477 @default.
- W2564856904 cites W130708379 @default.
- W2564856904 cites W1427174644 @default.
- W2564856904 cites W1506478314 @default.
- W2564856904 cites W1532586942 @default.
- W2564856904 cites W1535810264 @default.
- W2564856904 cites W1593678010 @default.
- W2564856904 cites W1934458198 @default.
- W2564856904 cites W1963947298 @default.
- W2564856904 cites W1964281299 @default.
- W2564856904 cites W1973614149 @default.
- W2564856904 cites W1990225450 @default.
- W2564856904 cites W1992359780 @default.
- W2564856904 cites W1992741024 @default.
- W2564856904 cites W1996931407 @default.
- W2564856904 cites W2009801020 @default.
- W2564856904 cites W2011491452 @default.
- W2564856904 cites W2042227081 @default.
- W2564856904 cites W2055275161 @default.
- W2564856904 cites W2056778557 @default.
- W2564856904 cites W2057949999 @default.
- W2564856904 cites W2066421179 @default.
- W2564856904 cites W2066852506 @default.
- W2564856904 cites W2074641559 @default.
- W2564856904 cites W2086839628 @default.
- W2564856904 cites W2098010707 @default.
- W2564856904 cites W2098809490 @default.
- W2564856904 cites W2104182023 @default.
- W2564856904 cites W2111160280 @default.
- W2564856904 cites W2111927651 @default.
- W2564856904 cites W2131019288 @default.
- W2564856904 cites W2140073981 @default.
- W2564856904 cites W2140370341 @default.
- W2564856904 cites W2147468904 @default.
- W2564856904 cites W2150620897 @default.
- W2564856904 cites W2152644030 @default.
- W2564856904 cites W2154555738 @default.
- W2564856904 cites W2162800072 @default.
- W2564856904 cites W2168264487 @default.
- W2564856904 cites W2168843528 @default.
- W2564856904 cites W2169461225 @default.
- W2564856904 cites W2171143790 @default.
- W2564856904 cites W2172060328 @default.
- W2564856904 cites W2180474751 @default.
- W2564856904 cites W2299561166 @default.
- W2564856904 cites W2299592321 @default.
- W2564856904 cites W2300305891 @default.
- W2564856904 cites W2395621591 @default.
- W2564856904 cites W2404948481 @default.
- W2564856904 cites W2463516579 @default.
- W2564856904 cites W2498412850 @default.
- W2564856904 cites W2786724047 @default.
- W2564856904 cites W2978757628 @default.
- W2564856904 cites W3141714753 @default.
- W2564856904 doi "https://doi.org/10.5555/3195638.3195686" @default.
- W2564856904 hasPublicationYear "2016" @default.
- W2564856904 type Work @default.
- W2564856904 sameAs 2564856904 @default.
- W2564856904 citedByCount "62" @default.
- W2564856904 countsByYear W25648569042017 @default.
- W2564856904 countsByYear W25648569042018 @default.
- W2564856904 countsByYear W25648569042019 @default.
- W2564856904 countsByYear W25648569042020 @default.
- W2564856904 countsByYear W25648569042021 @default.
- W2564856904 countsByYear W25648569042022 @default.
- W2564856904 crossrefType "proceedings-article" @default.
- W2564856904 hasAuthorship W2564856904A5059614371 @default.
- W2564856904 hasAuthorship W2564856904A5066100959 @default.
- W2564856904 hasAuthorship W2564856904A5087128492 @default.
- W2564856904 hasConcept C111919701 @default.
- W2564856904 hasConcept C144240696 @default.
- W2564856904 hasConcept C165696696 @default.
- W2564856904 hasConcept C175291020 @default.
- W2564856904 hasConcept C177264268 @default.
- W2564856904 hasConcept C178489894 @default.
- W2564856904 hasConcept C199360897 @default.
- W2564856904 hasConcept C2776760102 @default.
- W2564856904 hasConcept C2778579508 @default.
- W2564856904 hasConcept C38652104 @default.
- W2564856904 hasConcept C41008148 @default.
- W2564856904 hasConcept C49289754 @default.
- W2564856904 hasConcept C553261973 @default.
- W2564856904 hasConceptScore W2564856904C111919701 @default.
- W2564856904 hasConceptScore W2564856904C144240696 @default.
- W2564856904 hasConceptScore W2564856904C165696696 @default.
- W2564856904 hasConceptScore W2564856904C175291020 @default.
- W2564856904 hasConceptScore W2564856904C177264268 @default.
- W2564856904 hasConceptScore W2564856904C178489894 @default.
- W2564856904 hasConceptScore W2564856904C199360897 @default.
- W2564856904 hasConceptScore W2564856904C2776760102 @default.