Reza Mirzazade Farkhani

dblp:228/8232 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
2since 2021 · last 2021
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2021 Finding Bugs Using Your Own Code: Detecting Functionally-similar yet Inconsistent Code
Mansour Ahmadi, Reza Mirzazade Farkhani, Long Lu
USENIX Security Symposium2
2021 PTAuth: Temporal Memory Safety via Robust Points-to Authentication
Reza Mirzazade Farkhani, Mansour Ahmadi, Long Lu
USENIX Security Symposium1
2020 MEUZZ: Smart Seed Scheduling for Hybrid Fuzzing
Yaohui Chen 0001, Mansour Ahmadi, Reza Mirzazade Farkhani, Long Lu
RAID3
2018 On the Effectiveness of Type-based Control Flow Integrity
abstract
Control flow integrity (CFI) has received significant attention in the community to combat control hijacking attacks in the presence of memory corruption vulnerabilities. The challenges in creating a practical CFI has resulted in the development of a new type of CFI based on runtime type checking (RTC). RTC-based CFI has been implemented in a number of recent practical efforts such as GRSecurity Reuse Attack Protector (RAP) and LLVM-CFI. While there has been a number of previous efforts that studied the strengths and limitations of other types of CFI techniques, little has been done to evaluate the RTC-based CFI. In this work, we study the effectiveness of RTC from the security and practicality aspects. From the security perspective, we observe that type collisions are abundant in sufficiently large code bases but exploiting them to build a functional attack is not straightforward. Then we show how an attacker can successfully bypass RTC techniques using a variant of ROP attacks that respect type checking (called TROP) and also built two proof-of-concept exploits, one against Nginx web server and the other against Exim mail server. We also discuss practical challenges of implementing RTC. Our findings suggest that while RTC is more practical for applying CFI to large code bases, its policy is not strong enough when facing a motivated attacker.
Reza Mirzazade Farkhani, Saman Jafari, Sajjad Arshad, William K. Robertson, Engin Kirda, Hamed Okhravi
ACSAC1