Matches in SemOpenAlex for { <https://semopenalex.org/work/W4242926647> ?p ?o ?g. }
- W4242926647 abstract "Address Space Layout Randomization (ASLR) is a widely-used technique that protects systems against a range of attacks. ASLR works by randomizing the offset of key program segments in virtual memory, making it difficult for an attacker to derive the addresses of specific code objects and consequently redirect the control flow to this code. In this paper, we develop an attack to derive kernel and user-level ASLR offset using a side-channel attack on the branch target buffer (BTB). Our attack exploits the observation that an adversary can create BTB collisions between the branch instructions of the attacker process and either the user-level victim process or on the kernel executing on its behalf. These collisions, in turn, can impact the timing of the attacker's code, allowing the attacker to identify the locations of known branch instructions in the address space of the victim process or the kernel. We demonstrate that our attack can reliably recover kernel ASLR in about 60 milliseconds when performed on a real Haswell processor running a recent version of Linux. Finally, we describe several possible protection mechanisms, both in software and in hardware." @default.
- W4242926647 created "2022-05-12" @default.
- W4242926647 creator A5059614371 @default.
- W4242926647 creator A5066100959 @default.
- W4242926647 creator A5087128492 @default.
- W4242926647 date "2016-10-01" @default.
- W4242926647 modified "2023-10-01" @default.
- W4242926647 title "Jump over ASLR: Attacking branch predictors to bypass ASLR" @default.
- W4242926647 cites W1506478314 @default.
- W4242926647 cites W1934458198 @default.
- W4242926647 cites W1963947298 @default.
- W4242926647 cites W1964281299 @default.
- W4242926647 cites W1973614149 @default.
- W4242926647 cites W1990225450 @default.
- W4242926647 cites W1992359780 @default.
- W4242926647 cites W1992741024 @default.
- W4242926647 cites W1996931407 @default.
- W4242926647 cites W2009801020 @default.
- W4242926647 cites W2011491452 @default.
- W4242926647 cites W2042227081 @default.
- W4242926647 cites W2055275161 @default.
- W4242926647 cites W2057949999 @default.
- W4242926647 cites W2066421179 @default.
- W4242926647 cites W2066852506 @default.
- W4242926647 cites W2074641559 @default.
- W4242926647 cites W2086839628 @default.
- W4242926647 cites W2098010707 @default.
- W4242926647 cites W2098809490 @default.
- W4242926647 cites W2111160280 @default.
- W4242926647 cites W2140073981 @default.
- W4242926647 cites W2140370341 @default.
- W4242926647 cites W2147468904 @default.
- W4242926647 cites W2150620897 @default.
- W4242926647 cites W2162800072 @default.
- W4242926647 cites W2168264487 @default.
- W4242926647 cites W2168843528 @default.
- W4242926647 cites W2169461225 @default.
- W4242926647 cites W2171143790 @default.
- W4242926647 cites W2172060328 @default.
- W4242926647 cites W2180474751 @default.
- W4242926647 cites W2299561166 @default.
- W4242926647 cites W2299592321 @default.
- W4242926647 cites W2404948481 @default.
- W4242926647 cites W2498412850 @default.
- W4242926647 cites W3141714753 @default.
- W4242926647 doi "https://doi.org/10.1109/micro.2016.7783743" @default.
- W4242926647 hasPublicationYear "2016" @default.
- W4242926647 type Work @default.
- W4242926647 citedByCount "102" @default.
- W4242926647 countsByYear W42429266472016 @default.
- W4242926647 countsByYear W42429266472017 @default.
- W4242926647 countsByYear W42429266472018 @default.
- W4242926647 countsByYear W42429266472019 @default.
- W4242926647 countsByYear W42429266472020 @default.
- W4242926647 countsByYear W42429266472021 @default.
- W4242926647 countsByYear W42429266472022 @default.
- W4242926647 countsByYear W42429266472023 @default.
- W4242926647 crossrefType "proceedings-article" @default.
- W4242926647 hasAuthorship W4242926647A5059614371 @default.
- W4242926647 hasAuthorship W4242926647A5066100959 @default.
- W4242926647 hasAuthorship W4242926647A5087128492 @default.
- W4242926647 hasConcept C111919701 @default.
- W4242926647 hasConcept C144240696 @default.
- W4242926647 hasConcept C165696696 @default.
- W4242926647 hasConcept C175291020 @default.
- W4242926647 hasConcept C177264268 @default.
- W4242926647 hasConcept C178489894 @default.
- W4242926647 hasConcept C199360897 @default.
- W4242926647 hasConcept C2776760102 @default.
- W4242926647 hasConcept C2778579508 @default.
- W4242926647 hasConcept C38652104 @default.
- W4242926647 hasConcept C41008148 @default.
- W4242926647 hasConcept C49289754 @default.
- W4242926647 hasConcept C553261973 @default.
- W4242926647 hasConceptScore W4242926647C111919701 @default.
- W4242926647 hasConceptScore W4242926647C144240696 @default.
- W4242926647 hasConceptScore W4242926647C165696696 @default.
- W4242926647 hasConceptScore W4242926647C175291020 @default.
- W4242926647 hasConceptScore W4242926647C177264268 @default.
- W4242926647 hasConceptScore W4242926647C178489894 @default.
- W4242926647 hasConceptScore W4242926647C199360897 @default.
- W4242926647 hasConceptScore W4242926647C2776760102 @default.
- W4242926647 hasConceptScore W4242926647C2778579508 @default.
- W4242926647 hasConceptScore W4242926647C38652104 @default.
- W4242926647 hasConceptScore W4242926647C41008148 @default.
- W4242926647 hasConceptScore W4242926647C49289754 @default.
- W4242926647 hasConceptScore W4242926647C553261973 @default.
- W4242926647 hasLocation W42429266471 @default.
- W4242926647 hasOpenAccess W4242926647 @default.
- W4242926647 hasPrimaryLocation W42429266471 @default.
- W4242926647 hasRelatedWork W154428344 @default.
- W4242926647 hasRelatedWork W2002972382 @default.
- W4242926647 hasRelatedWork W2354398839 @default.
- W4242926647 hasRelatedWork W2371792015 @default.
- W4242926647 hasRelatedWork W2373778029 @default.
- W4242926647 hasRelatedWork W2377509977 @default.
- W4242926647 hasRelatedWork W2484918119 @default.
- W4242926647 hasRelatedWork W3026829828 @default.
- W4242926647 hasRelatedWork W4226318955 @default.
- W4242926647 hasRelatedWork W972100831 @default.