Windows 7 Forums


Windows 7: On the effectiveness of DEP and ASLR

13 Dec 2010  
JMH

Win 7 Ultimate 64-bit. SP1.
1,236 posts
 
 
On the effectiveness of DEP and ASLR

Quote:

DEP (Data Execution Prevention) and ASLR (Address Space Layout Randomization) have proven themselves to be important and effective countermeasures against the types of exploits that we see in the wild today. Of course, any useful mitigation technology will attract scrutiny, and over the past year there has been an increasing amount of research and discussion on the subject of bypassing DEP and ASLR [1,2]. In this blog post we wanted to spend some time discussing the effectiveness of these mitigations by providing some context for the bypass techniques that have been outlined in attack research. The key points that should be taken away from this blog post are:
  • DEP and ASLR are designed to increase an attacker's exploit development costs and decrease their return on investment.
  • The combination of DEP and ASLR is very effective at breaking the types of exploits we see in the wild today, but there are circumstances where they can both be bypassed.
  • Exploits targeting Microsoft and third party vulnerabilities have been created that are capable of bypassing DEP and ASLR in the context of browsers and third party applications.
  • We are currently not aware of any remote exploits that are capable of bypassing DEP and ASLR in the context of in-box Windows services and various other application domains.
  • Knowledge of potential bypass techniques directly informs our future work to improve the robustness and resiliency of DEP, ASLR, and our other mitigation technologies.
On the effectiveness of DEP and ASLR - Security Research & Defense - Site Home - TechNet Blogs

My System SpecsSystem Spec

13 Dec 2010  
Lomai

Win7 HP (x64)/Win7 Ultimate (x64)
1,207 posts
 
 

Thanks for the informative post Jan.
Have a great day
My System SpecsSystem Spec
Reply

 On the effectiveness of DEP and ASLR problems?



Thread Tools



Similar help and support threads for: On the effectiveness of DEP and ASLR
Thread Forum
Is SAS loosing its effectiveness? System Security
Solved MSE effectiveness ? System Security
PE/COFF Rebasing & ASLR Software
Speedboost effectiveness Performance & Maintenance


All times are GMT -5. The time now is 04:52 AM.



Windows 7 Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows 7" and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd