N.V. Gololobov1, E.Yu. Pavlenko2, N.N. Samarin3
1,2 Peter the Great St. Petersburg Polytechnic University (Saint Petersburg, Russia)
3 Moscow Technical University of Communications and Informatics (Moscow, Russia)
3 samarin_nik@mail.ru
The scientific and technical problem under investigation stems from the rise in cyber threats designed to exploit vulnerabilities in software code by malicious actors utilising the concept of back-oriented programming. When carrying out such attacks, attackers form malicious chains from instructions already present in memory, which, from the processor’s perspective, appear as a legitimate sequence of function calls and returns. This enables attackers to bypass antivirus software and other modern protection methods.
The study examines systemic mechanisms for protection against cyber threats and concludes that none of the measures considered can completely neutralise the threat. A pattern has been identified whereby overhead costs increase as the accuracy of control integrity monitoring improves. A classification of cyberattack scenarios is presented using the concept of reverse-oriented programming, along with their relationship to defence mechanisms. The most promising approach to countering this class of cyber threats is identified, consisting of dynamically changing the location of the code during its execution to prevent an attacker from exploiting a fixed address space for instructions.
Gololobov N.V., Pavlenko E.Yu., Samarin N.N. Analysis of software attack scenarios involving the exploitation of vulnerabilities and the construction of ROP chains // Radiotekhnika. 2026. V. 90. № 8. P. 131−139. DOI: https://doi.org/10.18127/j00338486-202608-12
- Bansal A., Mishra D. A practical analysis of ROP attacks. arXiv preprint arXiv:2111.03537. 2021.
- Zhang T. et al. SeBROP: blind ROP attacks without returns. Frontiers of Computer Science. 2022. V. 16. № 4. Р. 164818.
- Das S. et al. ROPSentry: Runtime defense against ROP attacks using hardware performance counters. Computers & Security. 2018. V. 73. Р 374-388.
- Zegzhda D.P., Aleksandrova E.B., Kalinin M.O. i dr. Kiberbezopasnost' cifrovoj industrii. Teoriya i praktika funkcional'noj ustojchivosti k kiberatakam. M.: Goryachaya liniya - Telekom. 2021. 560 s. (in Russian).
- Zubkov E.A., Ovasapyan T.D., Moskvin D.A., Zegzhda D.P. Informacionnaya bezopasnost' kiberfizicheskih sistem s tochki zreniya metodov modelirovaniya sistem. Materialy dokladov nauch.-praktich. konf. «Nedelya nauki IKNK». SPb: Sankt-Peterburgskij politekhnicheskij universitet Petra Velikogo. 2024. S. 68-70 (in Russian).
- Aristizabal D.H., Rodriguez D.M., Guevara R.Y. Measuring ASLR implementations on modern operating systems. 2013 47th International Carnahan Conference on Security Technology (ICCST). IEEE. 2013. С. 1-6.
- Evtyushkin D., Ponomarev D., Abu-Ghazaleh N. Jump over ASLR: Attacking branch predictors to bypass ASLR. 2016 49th Annual IEEE/ACM International Symposium on Microarchitecture (MICRO). IEEE. 2016. С. 1-13.
- Lehniger K., Langendorfer P. Window canaries: Re-thinking stack canaries for architectures with register windows. IEEE Transactions on Dependable and Secure Computing. 2022. V. 20. № 6. Р. 4637-4647.
- Depuydt H. et al. Do we still need canaries in the coal mine? Measuring shadow stack effectiveness in countering stack smashing. International Conference on Availability, Reliability and Security. Cham: Springer Nature Switzerland. 2025. Р. 193-205.
- Marco-Gisbert H., Ripoll I. Preventing brute force attacks against stack canary protection on networking servers. 2013 IEEE 12th International Symposium on Network Computing and Applications. IEEE. 2013. Р. 243-250.
- Zouahi H. Gamifying Cybersecurity Education: A CTF-based Approach to Engaging Students in Software Security Laboratories. Proceedings of the Canadian Engineering Education Association (CEEA). 2023.
- Parida T., Das S. Analyzing PTM attack traces through PageDumper: A case study. 2022 IEEE 7th International Conference for Convergence in Technology (I2CT). IEEE. 2022. Р. 1-7.
- Pewny J., Holz T. Control-flow restrictor: Compiler-based CFI for iOS. Proceedings of the 29th Annual Computer Security Applications Conference. 2013. Р. 309-318.
- Muntean P. et al. Analyzing control flow integrity with LLVM-CFI. Proceedings of the 35th Annual Computer Security Applications Conference. 2019. Р. 584-597.
- Zou C., Gao Y., Xue J. Practical software-based shadow stacks on x86-64. ACM Transactions on Architecture and Code Optimization (TACO). 2022. V. 19. № 4. Р. 1-26.
- Choi W. et al. SuM: Efficient shadow stack protection on ARM Cortex-M. Computers & Security. 2024. V. 136. Р. 103568.
- Walcott-Justice K., Mars J., Soffa M. L. Theme: A system for testing by hardware monitoring events. Proceedings of the 2012 International Symposium on Software Testing and Analysis. 2012. Р. 12-22.
- Lopez G. Fuzzing with Performance Monitoring and Tracing Hardware. Georgia Institute of Technology. 2022.
- Huang K. et al. The taming of the stack: Isolating stack data from memory errors. 2022.
- Chen G. et al. Safestack: Automatically patching stack-based buffer overflow vulnerabilities. IEEE Transactions on Dependable and Secure Computing. 2013. V. 10. № 6. P. 368-379.

