BlueHat security finalists announced

Powered by SC Magazine
 

Three finalists eye defense against Return Oriented Programming attacks 

Microsoft has announced the three finalists of its BlueHat defensive security competition, each handpicked for their techniques to mitigate Return Oriented-Programming (ROP) exploits.

In a nutshell, ROP allows attackers to execute code in the presence of non executable memory segments and code signing. ROP attackers have control of the call stack to execute instructions ahead of the return instruction in subroutines of code. The execution of instructions from inside a program avoids defensive measures designed to stop execution from user-controlled memory.

One of the defensive measures will see a researcher win the top prize of US$250,000, with second prize US$50,000 and third place scores a subscription to Microsoft’s developer network (MSDN) services valued at about US$10,000.

Competitors were allowed to keep their intellectual property and Microsoft would receive free licence to use it.

Respected security researcher Jared DeMott told SC he was glad to have reached the finals.

His submission, called /ROP, uses a whitelist to check the integrity of return addresses.

“I targeted ROP because it is currently the most used technique to exploit fully compiled software,” DeMott said.

“/ROP was designed with the Windows platform in mind, so I’m hoping they will implement it.  Other operating systems could implement similar strategies if they desire.”

He didn’t keep tabs on how long it took to build the system, saying only that “it took a while”.

Columbia University PhD graduate and security researcher Vasillis Pappas submitted kBouncer, which would use common hardware features to detect and mitigate abnormal control transfers.

A third researcher, Ivan Fratric from Croatia developed ROPGuard that defines a set of checks used to detect functions used in ROP.

Microsoft received 20 entries for the competition between 3 August last year and 1 April. Each submission was weighted first on impact, then robustness and practicality and functionality.

Copyright © SC Magazine, Australia


BlueHat security finalists announced
 
 
 
Top Stories
NSW to build its own myGov
Service NSW digital profiles available by September.
 
Australia's leaders agree to end GST-free online goods
Gerry Harvey may finally get his way.
 
What to expect from Abbott's national cyber security strategy
Key policy architect reveals focus of new document.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Microsoft reveals Microsoft Send, a new enterprise chat app to rival Slack
Jul 27, 2015
Microsoft Send is MSN Messenger for grownups, and you could be using it at work very soon
Developers offered $500,000 grants to find HoloLens uses
Jul 8, 2015
Can augmented-reality end up in business?
Microsoft Tossup: The planning app for unorganised groups of friends
Jul 8, 2015
App allows friends to research venues, vote on plans and chat. And depending on how you run your ...
Windows 10 drops 29 July... but only for some
Jul 6, 2015
If you've reserved your copy of Windows 10 and are keenly awaiting its 29 July release, don't ...
Xerocon is heading to Melbourne!
Jul 1, 2015
We're not saying Xero is our FAVOURITE or anything, but Xero's 2015 Xerocon conference is being ...
Latest Comments
Polls
Should law enforcement be able to buy and use exploits?



   |   View results
Yes
  13%
 
No
  51%
 
Only in special circumstances
  17%
 
Yes, but with more transparency
  19%
TOTAL VOTES: 699

Vote