Address Space Layout Randomization Comparative Analysis on Windows 10 and Ubuntu 18.04 LTS

Autor: Martiño Rivera-Dourado, Raquel Vázquez Díaz, Pilar Vila Avendaño, Rubén Pérez-Jove, José M. Vázquez-Naya
Rok vydání: 2021
Předmět:
Zdroj: RUC. Repositorio da Universidade da Coruña
instname
DOI: 10.3390/engproc2021007026
Popis: Presented at the 4th XoveTIC Conference, A Coruña, Spain, 7–8 October 2021 [Abstract] Memory management is one of the main tasks of an Operating System, where the data of each process running in the system is kept. In this context, there exist several types of attacks that exploit memory-related vulnerabilities, forcing Operating Systems to feature memory protection techniques that make difficult to exploit them. One of these techniques is ASLR, whose function is to introduce randomness into the virtual address space of a process. The goal of this work was to measure, analyze and compare the behavior of ASLR on the 64-bit versions of Windows 10 and Ubuntu 18.04 LTS. The results have shown that the implementation of ASLR has improved significantly on these two Operating Systems compared to previous versions. However, there are aspects, such as partial correlations or a frequency distribution that is not always uniform, so it can still be improved. We wish to acknowledge the support received from the Centro de Investigación de Galicia “CITIC”. CITIC, as Research Center accredited by Galician University System, is funded by “Consellería de Cultura, Educación e Universidade from Xunta de Galicia”, supported in an 80% through ERDF, ERDF Operational Programme Galicia 2014–2020, and the remaining 20% by “Secretaría Xeral de Universidades” (Grant ED431G 2019/01). This work was also supported by the “Consellería de Cultura, Educación e Ordenación Universitaria” via the Consolidation and Structuring of Competitive Research Units—Competitive Reference Groups (ED431C 2018/49) and the COST Action 17124 DigForAsp, supported by COST (European Cooperation in Science and Technology, www.cost.eu, (accessed on 20 July 2021)) Xunta de Galicia; ED431G 2019/01 Xunta de Galicia; ED431C 2018/49
Databáze: OpenAIRE