Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

PROPS (Precision ROP Scanner)

This repository contains all the source code and all the artifacts needed to replicate the results described in our paper:

J. Sándor, R. Nagy, L. Buttyán, PROPS: Learning Stack Patterns for ROP Detection on Legacy ARM-based Devices, 21st International Conference on Availability, Reliability and Security (ARES), 2026.

Install PROPS

The modules have been tested with Python 3.11

For using PROPS as module:

  • pip install -e .

For basic scripts (like PCA related measurements), install dependencies:

  • pip install -r requirements/requirements-basic.txt

For execute scripts that use angrop or pwntools, install dependencies in different virtual environment:

  • pip install -r requirements/requirements-angrop.txt

Download the data

  • You can download our dataset (.zip) from:

https://cloud.crysys.hu/s/dcsJ2HnXD799DGe

  • Extract the .zip into the PROPS/data folder

Information:

  • rpi-binaries contains the executable binaries
  • all_bins.txt contains the names of the executable binaries
  • useful_bins.txt contains the names of binaries, from which we were able to collect clean stack contents
  • few_bins.txt contains the filenames that we used for ROP chain generation and for the runtime measurements
  • gcores-main folder contains the memory snapshots
  • stack-states folder contain the stack content of benign executions
  • gadgets folder contains the angrop objects after preprocessing

Collect the data

If you want to collect your own data from your RPI3, you can do that with the following scripts.

Collect the clean stack states

  • python3 extract/get_breakpoints.py

  • to create gcore snapshots and stack states run on RPI3:

./mem-dump.sh

Generate ROP chains

Preprocess binaries with angrop:

  • python3 gadget/save_angrop_gadgets.py

Create ROP chains:

  • python3 gadget/system-chain.py
  • python3 gadget/mmap-chain.py
  • python3 gadget/mprotect-chain.py

Extract feature vectors

In data/features folder there are already extracted feature vectors, but you can also reproduce them:

  • python3 extract/gcore_feature_extractor.py

  • python3 detection/feature_provider.py

Run PCA

  • python3 detection/pca.py --action train

  • python3 detection/pca.py --action test

  • python3 detection/pca.py --action cross-validate

  • python3 detection/cv-results.py

Runtime overhead measurements

To evaluate the captured timings:

  • python3 runtime/parse_kernel_log.py

  • python3 runtime/parse_timings.py

Kernel module usage examples

From poc/testapp compile the test program:

  • make

From poc/erops-lkm compile (the kernel must support uprobes feature) and add the module:

  • make
  • sudo insmod erops.ko filename=~/PROPS/poc/testapp/test offset_array=1080

From poc/supplicant compile and run the supplicant user-space program:

  • make
  • sudo ./supplicant

In a new terminal run the test program and check the kernel logs:

  • ./test
  • sudo dmesg

To remove kernel module:

  • sudo rmmod erops

Test PROPS on Crashmail 1.6

  • to run with exploit ./crashmail SETTINGS $(cat exploit_payload.bin) | cat

Trigger breakpoint:

  • 0x12484 - 0x10000 = 0x2484 -> 9348 in decimal

From ~/PROPS/poc/erops-lkm folder:

  • sudo insmod erops.ko filename=~/PROPS/data/binaries/crashmail offset_array=9348

From ~/PROPS/poc/erops-supplicant folder:

  • sudo ./supplicant

Run crashmail with or without the exploit payload, and check kernel log.

In ~/PROPS/poc/erops-supplicant dump.dat is created

Run extract/supplicant_feature_extractor.py to extract features:

  • Supplicant Clean Features: WX??W?W????SWW?W????WW??????????
  • Supplicant ROP Features: ?GS?F??????SWW?W????WW??????????

Run PCA check:

  • python3 detection/pca.py --action check --seq "WX??W?W????SWW?W????WW??????????"
  • python3 detection/pca.py --action check --seq "?GS?F??????SWW?W????WW??????????"

Run PCA check on RPi3:

  • python3 poc/detector/pca_detect.py --seq "WX??W?W????SWW?W????WW??????????"
  • python3 poc/detector/pca_detect.py --seq "?GS?F??????SWW?W????WW??????????"

About

Precision ROP Scanner

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages