This repository contains all the source code and all the artifacts needed to replicate the results described in our paper:
J. Sándor, R. Nagy, L. Buttyán, PROPS: Learning Stack Patterns for ROP Detection on Legacy ARM-based Devices, 21st International Conference on Availability, Reliability and Security (ARES), 2026.
The modules have been tested with Python 3.11
For using PROPS as module:
- pip install -e .
For basic scripts (like PCA related measurements), install dependencies:
- pip install -r requirements/requirements-basic.txt
For execute scripts that use angrop or pwntools, install dependencies in different virtual environment:
- pip install -r requirements/requirements-angrop.txt
- You can download our dataset (.zip) from:
https://cloud.crysys.hu/s/dcsJ2HnXD799DGe
- Extract the .zip into the PROPS/data folder
Information:
- rpi-binaries contains the executable binaries
- all_bins.txt contains the names of the executable binaries
- useful_bins.txt contains the names of binaries, from which we were able to collect clean stack contents
- few_bins.txt contains the filenames that we used for ROP chain generation and for the runtime measurements
- gcores-main folder contains the memory snapshots
- stack-states folder contain the stack content of benign executions
- gadgets folder contains the angrop objects after preprocessing
If you want to collect your own data from your RPI3, you can do that with the following scripts.
-
python3 extract/get_breakpoints.py
-
to create gcore snapshots and stack states run on RPI3:
./mem-dump.sh
Preprocess binaries with angrop:
- python3 gadget/save_angrop_gadgets.py
Create ROP chains:
- python3 gadget/system-chain.py
- python3 gadget/mmap-chain.py
- python3 gadget/mprotect-chain.py
In data/features folder there are already extracted feature vectors, but you can also reproduce them:
-
python3 extract/gcore_feature_extractor.py
-
python3 detection/feature_provider.py
-
python3 detection/pca.py --action train
-
python3 detection/pca.py --action test
-
python3 detection/pca.py --action cross-validate
-
python3 detection/cv-results.py
To evaluate the captured timings:
-
python3 runtime/parse_kernel_log.py
-
python3 runtime/parse_timings.py
From poc/testapp compile the test program:
- make
From poc/erops-lkm compile (the kernel must support uprobes feature) and add the module:
- make
- sudo insmod erops.ko filename=~/PROPS/poc/testapp/test offset_array=1080
From poc/supplicant compile and run the supplicant user-space program:
- make
- sudo ./supplicant
In a new terminal run the test program and check the kernel logs:
- ./test
- sudo dmesg
To remove kernel module:
- sudo rmmod erops
- to run with exploit ./crashmail SETTINGS $(cat exploit_payload.bin) | cat
Trigger breakpoint:
- 0x12484 - 0x10000 = 0x2484 -> 9348 in decimal
From ~/PROPS/poc/erops-lkm folder:
- sudo insmod erops.ko filename=~/PROPS/data/binaries/crashmail offset_array=9348
From ~/PROPS/poc/erops-supplicant folder:
- sudo ./supplicant
Run crashmail with or without the exploit payload, and check kernel log.
In ~/PROPS/poc/erops-supplicant dump.dat is created
Run extract/supplicant_feature_extractor.py to extract features:
- Supplicant Clean Features: WX??W?W????SWW?W????WW??????????
- Supplicant ROP Features: ?GS?F??????SWW?W????WW??????????
Run PCA check:
- python3 detection/pca.py --action check --seq "WX??W?W????SWW?W????WW??????????"
- python3 detection/pca.py --action check --seq "?GS?F??????SWW?W????WW??????????"
Run PCA check on RPi3:
- python3 poc/detector/pca_detect.py --seq "WX??W?W????SWW?W????WW??????????"
- python3 poc/detector/pca_detect.py --seq "?GS?F??????SWW?W????WW??????????"