跳到主要內容

臺灣博碩士論文加值系統

(216.73.217.127) 您好!臺灣時間:2026/07/30 13:22
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

: 
twitterline
研究生:陳泓文
研究生(外文):Chen, Hung-Wen
論文名稱:結合滲透測試框架之攻擊脅迫強化系統
論文名稱(外文):A Systematic Exploit Strengthening Method Integrating with Penetration Testing Framework
指導教授:黃世昆黃世昆引用關係
指導教授(外文):Huang, Shih-Kun
口試委員:許富皓宋定懿黃世昆
口試委員(外文):Hsu, Fu-HauSung, Ting-YiHuang, Shih-Kun
口試日期:2015-05-29
學位類別:碩士
校院名稱:國立交通大學
系所名稱:資訊科學與工程研究所
學門:工程學門
學類:電資工程學類
論文種類:學術論文
論文出版年:2015
畢業學年度:103
語文別:中文
論文頁數:44
中文關鍵詞:脅迫強化返回導向編程自動脅迫生成軟體安全軟體弱點後脅迫框架
外文關鍵詞:Exploit StrengtheningROPAutomatic Exploit GenerationSoftware SecuritySoftware VulnerabilityPost Exploitation Framework
相關次數:
  • 被引用被引用:1
  • 點閱點閱:1014
  • 評分評分:
  • 下載下載:105
  • 收藏至我的研究室書目清單書目收藏:1
近年來,由於軟體品質良莠不齊,軟體漏洞持續揭露、駭客攻擊的事件層出不窮,軟體安全議題因此逐漸受到重視。在現今高度資訊化的社會環境中,這些漏洞甚至危害到公共基礎建設、進而可能影響到人身安全。儘管目前作業系統已支援多種保護機制,例如:資料防止執行 (W⊕X or DEP)、位址空間配置隨機載入 (ASLR)等,但仍有繞過這些保護機制的攻擊方法,例如:返回導向編程 (ROP, Return-Oriented Programming)。
在本篇論文中,我們提出改良 ROP,有效繞過保護機制的脅迫強化方法 (Exploit Strengthening Method)並結合自動脅迫生成 (Automatic Exploit Generation, CRAX),產生可繞過保護機制的脅迫 (Exploit)。我們的方法 (Exploit Strengthening Method)主要是運用返回導向編程 (ROP)的技術,透過蒐集受測程式的機器語言指令片段 (稱為Gadget),經過Gadget的篩選,組合出攻擊的目標程式,例如:執行”/bin/sh”程式、產生Reverse/Bind TCP Shell後門。自動脅迫生成 (Automatic Exploit Generation, CRAX)則自動將軟體漏洞 (Vulnerability)轉換成可以運用的脅迫 (Exploit)。脅迫成功後,將Exploit以模組的形式匯入至Metasploit後脅迫框架 (Post Exploitation Framework)中,測試者只要透過Metasploit產生符合自己環境的脅迫執行檔或代碼,就可以在第一時間檢測相關系統,判斷與找尋可被脅迫利用的高危險性漏洞。
我們的方法經評估,優於現行公開且最普遍運用的系統:ROPgadget,10個大於100KB動態鏈結程式中,相較於 ROPgadget 只有三個成功,我們全部都能成功生成。我們也是唯一能結合後脅迫框架的脅迫工具鏈。

Due to software quality issues, recent attacks on various systems are getting serious, and the software security issues therefore become an important research topic. These attacks on the software vulnerability will not only endanger the information infrastructure, but also impact the human safety. To improve the overall robustness of the system, we need a penetration test system to audit related systems. We have proposed the concept of the exploit toolchain to automate the whole process of fuzzing, exploitation, and post-exploitation integration with the metasploit framework.
For the exploitation process, we must be able to bypass the recent protections and mitigations of the operating system, for example ASLR (Address space layout randomization) and DEP (Data Execution Prevention). We have enhanced the ROP (Return-oriented programming) technique to bypass ASLR and DEP protections by searching gadgets with larger sizes.
We evaluate our system by generating ROP payloads from ten target programs in the size greater than 100K bytes. Compared with the results of another popular ROP tool, called ROPgadget, only three targets have been succeeded. We can also integrate the generated exploits into the Metasploit framework.

摘要 i
ABSTRACT iii
誌謝 v
目錄 vi
圖目錄 ix
表目錄 xi
演算法目錄 xi
程式碼目錄 xi
1. 簡介 1
1.1. 背景 3
1.1.1. 軟體安全保護機制 (Protection mechanisms) 3
1.1.1.1. W⊕X (Write xor Execute) 3
1.1.1.2. 位址空間配置隨機載入 (ASLR, Address Space Layout Randomization) 4
1.1.2. 軟體安全脅迫技術 (Exploit technique) 5
1.1.2.1. Return-to-Stack Attack 5
1.1.2.2. Return-to-Libc Attack 5
1.1.2.3. Return-Oriented Programming 6
1.1.3. 自動脅迫產生器 (Automatic Exploit Generations, CRAX) 7
1.1.3.1. 符號執行 (Symbolic Execution) 7
1.1.3.2. 單一路徑擬真執行 (Single Path Concolic Execution) 9
2. 相關研究 10
2.1. 返回導向編程 (Return-Oriented Programming) 10
2.1.1. ROPgadget 10
2.1.2. Q 10
2.1.3. LGadget 10
2.1.4. 其他 11
2.2. 後脅迫框架 (Post Exploitation Framework) 12
2.2.1. Metasploit 12
2.2.2. Meterpreter 12
2.2.3. Powersploit 12
3. 方法與實作 13
3.1. 脅迫強化方法 (Exploit Strengthening Method) 13
3.1.1. 機器語言指令片段搜尋 (Gadgets Search) 13
3.1.2. 機器語言指令片段排序與獨立性 (Gadgets Arrangement and Dependency) 15
3.2. 函式庫實作 18
3.2.1. ROP代碼函式庫 (ROP Payload API) 18
3.2.2. Turing Complete探討 19
3.2.2.1. 記憶體與暫存器的存取 19
3.2.2.2. 基本運算與邏輯 22
3.2.2.3. 控制流 - Unconditional Jump 22
3.2.2.4. 控制流 - Conditional Jump 24
3.2.2.5. 系統調用 28
3.2.3. 產生ROP 代碼 (ROP Payload) 29
4. 整合 30
4.1. 自動脅迫產生 (Automatic Exploit Generations) 30
4.1.1. 新舊CRAX比較 30
4.1.2. 轉換符號變數(Symbolic Variable) 31
4.1.3. 符號執行(Symbolic Execution) 32
4.1.4. 產生脅迫輸入(Exploit Input) 32
4.2. 後脅迫框架 (Post Exploitation Framework) 34
4.2.1. 設定Metasploit Handler 35
4.2.2. 執行ROP Payload 35
4.2.3. Metasploit取得目標機器控制權 36
5. 結果 37
5.1. Bypass W⊕X and ASLR 37
5.2. 與ROPgadget比較 39
5.3. 探討Gadget長度與ROP代碼成功率之關係 40
6. 結論與未來展望 41
6.1. 結論 41
6.2. 未來發展 42
參考文獻 43

1. Shacham, H., The Geometry of Innocent Flesh on the Bone: Return-into-libc without Function Calls (on the x86). Ccs'07: Proceedings of the 14th Acm Conference on Computer and Communications Security, 2007: p. 552-561.
2. Team, P. Pax address space layout randomization. Available from: http://pax.grsecurity.net/docs/aslr.txt.
3. Payer, M., Too much PIE is bad for performance. 2012.
4. Huang, S.K., et al. CRAX: Software Crash Analysis for Automatic Exploit Generation by Modeling Attacks as Symbolic Continuations. in Software Security and Reliability (SERE), 2012 IEEE Sixth International Conference on. 2012. IEEE.
5. 黃世昆, et al., 自動脅迫產生器發展現況與威脅分析. 資訊安全通訊, 2012. 18(3): p. 88-100.
6. Chipounov, V., V. Kuznetsov, and G. Candea, The S2E platform: Design, implementation, and applications. ACM Transactions on Computer Systems (TOCS), 2012. 30(1): p. 2.
7. Bellard, F. QEMU, a Fast and Portable Dynamic Translator. in USENIX Annual Technical Conference, FREENIX Track. 2005.
8. Maynor, D., Metasploit toolkit for penetration testing, exploit development, and vulnerability research. 2011: Elsevier.
9. c0ntex. Bypassing non-executable-stack during exploitation using return-to-libc. Available from: http://css.csail.mit.edu/6.858/2014/readings/return-to-libc.pdf.
10. Du, W. Return-to-libc Attack Lab. 2007; Available from: http://www.cis.syr.edu/~wedu/seed/Labs/Vulnerability/Return_to_libc/Return_to_libc.pdf.
11. King, J.C., Symbolic execution and program testing. Communications of the ACM, 1976. 19(7): p. 385-394.
12. Păsăreanu, C.S. and W. Visser, A survey of new trends in symbolic execution for software testing and analysis. International journal on software tools for technology transfer, 2009. 11(4): p. 339-353.
13. Sen, K. Concolic testing. in Proceedings of the twenty-second IEEE/ACM international conference on Automated software engineering. 2007. ACM.
14. Salwan, J. ROPgadget. Available from: https://github.com/JonathanSalwan/ROPgadget.
15. Schwartz, E.J., T. Avgerinos, and D. Brumley. Q: Exploit Hardening Made Easy. in USENIX Security Symposium. 2011.
16. Avgerinos, T., et al. AEG: Automatic Exploit Generation. in NDSS. 2011.
17. Brumley, D., et al. Automatic patch-based exploit generation is possible: Techniques and implications. in Security and Privacy, 2008. SP 2008. IEEE Symposium on. 2008. IEEE.
18. Chen, P., et al., DROP: Detecting return-oriented programming malicious code, in Information Systems Security. 2009, Springer. p. 163-177.
19. Cao, J., et al., LGadget: ROP Exploit based on Long Instruction Sequences. 2013.
20. Dullien, T., T. Kornau, and R.-P. Weinmann. A Framework for Automated Architecture-Independent Gadget Search. in WOOT. 2010.
21. Kornau, T., Return oriented programming for the ARM architecture. Master's thesis, Ruhr-Universitat Bochum, 2010.
22. Roemer, R.G., Finding the bad in good code: Automated return-oriented programming exploit discovery. 2009.
23. Security, O. Metasploit Meterpreter. Available from: http://www.offensive-security.com/metasploit-unleashed/About_Meterpreter.
24. Graeber, M. PowerSploit - A PowerShell Post-Exploitation Framework. Available from: https://github.com/mattifestation/PowerSploit.
25. Campbell, C. PowerSploit + Metasploit = Shells. Available from: http://obscuresecurity.blogspot.tw/2013/03/powersploit-metasploit-shells.html.
26. Nguyen Anh Quynh, C., Capstone: Next-Gen Disassembly Framework. 2014: Blackhat USA.
27. Burt, G.L. Linux System Call Table. 2004; Available from: http://docs.cs.up.ac.za/programming/asm/derick_tut/syscalls.html.

連結至畢業學校之論文網頁點我開啟連結
註: 此連結為研究生畢業學校所提供,不一定有電子全文可供下載,若連結有誤,請點選上方之〝勘誤回報〞功能,我們會盡快修正,謝謝!
QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top