Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

7/24/2013
01:11 AM
50%
50%

Visualization Helps Attackers Spot Flaws In Software's Armor

Using data visualization techniques, researchers make memory and randomization flaws easier to recognize, spotting vulnerabilities in anti-exploitation technology such as ASLR and DEP

Simple data visualization techniques can be used to find weaknesses in the software technologies designed to protect operating systems from exploitation, according to a pair of researchers who will present their findings at Black Hat USA next week.

Click here for more of Dark Reading's Black Hat articles.

The researchers, Georg Wicherski and Alexandru Radocea of security startup CrowdStrike, used space-filling fractals known as Hilbert Curves--the most famous of which are the heat maps for visualizing the Internet's address space--to map out memory page tables, using brighter colors to indicate more dangerous areas. The technique can help researchers better see problems in anti-exploitation techniques such as address-space layout randomization (ASLR) and data-execution prevention (DEP), Wicherski says.

"We wanted to find ways to make these concepts more accessible to more researchers," he says. "How do you see what is randomized, what is not randomized, and what is a potential vulnerability?"

Using the techniques, the researchers found that Android and other versions of Linux have flaws on the ARM architecture that significantly weaken exploitation mitigations. On ARM, the whole Linux kernel memory area is both writable and executable, allowing any memory-corruption bug to overwrite the kernel code, Wicherski says.

"You don't have to do any advanced exploitation techniques on ARM at all," Wicherski says.

The researchers also plan to demonstrate some weaknesses of iOS using visualizations of the operating system's address space.

To produce the maps, the researchers first categorized areas of memory by their permissions, whether each one was writable, executable or both. Attackers look for pages that are writable and executable and in a consistent location, because they can write their own malicious code to that section of memory and then execute it.

[Attackers cheated two widely respected Microsoft security features to wage targeted attacks via a previously unknown flaw in Internet Explorer. See New IE Zero-Day Attack Bypasses Key Microsoft Security Measures.]

Technologies like data-execution prevention (DEP) attempt to virtually separate the parts of memory to which data can be written and the parts of memory that can be executed. Address space layout randomization (ASLR) makes it hard for attackers to know where a certain section of memory will be located. Analyzing the implementation of these technologies can be hard, but visualization can help researchers spot patterns that they might not otherwise detect, says Ollie Whitehouse, associate director of the NCC Group, a security testing and compliance firm.

"Being able to identify pages that are both readable and writable is important," Whitehouse says. "The way that they did it is innovative, because humans are very visual and good at pattern recognition, so giving them visual representations of these problems can work extremely well."

The technique does not work against logic flaws or other types of code analysis. Yet, it could be a useful way for developers to visualize the way their code uses memory and more easily spot implementation flaws, says CrowdStrike's Wicherski. Vulnerability researchers can also use it to gauge the relative strength of a program's mitigations.

"If you have a new operating system that you want to attack and you want to understand how these mitigations work there and how effective they are, you can use this as a real tool," he says.

In addition, the technique could help developers that are not intimately familiar with how to identify and find memory flaws and weaknesses to see problems with their code, says NCC Group's Whitehouse.

"If you take security problems into the visualization realm, you open them up to people who might not be hardcore reverse engineers and security software analysts," he says.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
A Realistic Threat Model for the Masses
Lysa Myers, Security Researcher, ESET,  10/9/2019
USB Drive Security Still Lags
Dark Reading Staff 10/9/2019
Virginia a Hot Spot For Cybersecurity Jobs
Jai Vijayan, Contributing Writer,  10/9/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-17612
PUBLISHED: 2019-10-15
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter.
CVE-2019-17613
PUBLISHED: 2019-10-15
qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as demonstrated by a payload in...
CVE-2019-17395
PUBLISHED: 2019-10-15
In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
CVE-2019-17602
PUBLISHED: 2019-10-15
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.
CVE-2019-17394
PUBLISHED: 2019-10-15
In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.