Computer Science > Cryptography and Security
[Submitted on 27 Mar 2025]
Title:Non-control-Data Attacks and Defenses: A review
View PDF HTML (experimental)Abstract:In recent years, non-control-data attacks have be come a research hotspot in the field of network security, driven
by the increasing number of defense methods against control-flow
hijacking attacks. These attacks exploit memory vulnerabilities
to modify non-control data within a program, thereby altering its
behavior without compromising control-flow integrity. Research
has shown that non-control-data attacks can be just as damaging
as control-flow hijacking attacks and are even Turing complete,
making them a serious security threat. However, despite being
discovered long ago, the threat of non-control-data attacks has
not been adequately addressed. In this review, we first classify
non-control-data attacks into two categories based on their
evolution: security-sensitive function attacks and data-oriented
programming (DOP) attacks. Subsequently, based on the non control-data attack model, we categorize existing defense methods
into three main strategies: memory safety, data confidentiality,
and data integrity protection. We then analyze recent defense
techniques specifically designed for DOP attacks. Finally, we
identify the key challenges hindering the widespread adoption
of defenses against non-control-data attacks and explore future
research directions in this field.
References & Citations
Bibliographic and Citation Tools
Bibliographic Explorer (What is the Explorer?)
Connected Papers (What is Connected Papers?)
Litmaps (What is Litmaps?)
scite Smart Citations (What are Smart Citations?)
Code, Data and Media Associated with this Article
alphaXiv (What is alphaXiv?)
CatalyzeX Code Finder for Papers (What is CatalyzeX?)
DagsHub (What is DagsHub?)
Gotit.pub (What is GotitPub?)
Hugging Face (What is Huggingface?)
Papers with Code (What is Papers with Code?)
ScienceCast (What is ScienceCast?)
Demos
Recommenders and Search Tools
Influence Flower (What are Influence Flowers?)
CORE Recommender (What is CORE?)
arXivLabs: experimental projects with community collaborators
arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.
Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.
Have an idea for a project that will add value for arXiv's community? Learn more about arXivLabs.