Proceedings 2017 Network and Distributed System Security Symposium 2017
DOI: 10.14722/ndss.2017.23108
|View full text |Cite
|
Sign up to set email alerts
|

A Call to ARMs: Understanding the Costs and Benefits of JIT Spraying Mitigations

Abstract: JIT spraying allows an attacker to subvert a Just-In-Time compiler, introducing instruction sequences useful to the attacker into executable regions of the victim program's address space as a side effect of compiling seemingly innocuous code in a safe language like JavaScript. We present new JIT spraying attacks against Google's V8 and Mozilla's SpiderMonkey JavaScript engines on ARM. The V8 attack is the first JIT spraying attack not to rely on instruction decoding ambiguity, and the SpiderMonkey attack uses … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1

Citation Types

0
3
0

Year Published

2019
2019
2023
2023

Publication Types

Select...
3
3

Relationship

0
6

Authors

Journals

citations
Cited by 6 publications
(3 citation statements)
references
References 15 publications
0
3
0
Order By: Relevance
“…Despite the widespread support and implementation of DNSSEC among top-level domains, studies such as (Chung et al, 2017;Lian et al, 2013;Osterweil et al, 2008;Yang et al, 2011) have found that its adoption has been low, due to factors such as lack of support from local resolvers and server misconfigurations.…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation
“…Despite the widespread support and implementation of DNSSEC among top-level domains, studies such as (Chung et al, 2017;Lian et al, 2013;Osterweil et al, 2008;Yang et al, 2011) have found that its adoption has been low, due to factors such as lack of support from local resolvers and server misconfigurations.…”
Section: Related Workmentioning
confidence: 99%
“…The DNSSEC subsection of this work assesses the use of the DNSSEC protocol by municipal councils in Portugal. Figure 6 of DNSSEC among top-level domains, studies have found that its adoption by lower-level domains, such as municipal councils, has been low (Chung et al, 2017;Lian et al, 2013;Osterweil et al, 2008;Yang et al, 2011).…”
Section: Dnssecmentioning
confidence: 99%
“…The measurement results are publicly available. 1 Last, (iii) we develop and publish an open source tool with which operators can easily monitor their rollover themselves. 2 The registry of the Brazilian ccTLD .br used this tool to monitor their algorithm rollover in August 2018 [10], following our method.…”
mentioning
confidence: 99%