Microsoft’s Trustworthy Computing Group has released the Enhanced Mitigation Experience Toolkit (EMET) 3.5 Technology Preview, which includes new Return Oriented Programming (ROP) defenses inspired by BlueHat Prize contest finalist Ivan Fratric. The EMET 3.5 Technology Preview is a freely available security tool that makes it more difficult for attackers to exploit vulnerabilities and gain system access.
Mr. Fratric, who earned a Ph.D. in computer science and is a researcher at the University of Zagreb located in Zagreb, Croatia, submitted a solution called ROPGuard, which hinders attacks that leverage ROP. ROP is a technique that attackers use to combine short pieces of benign code, already present in a system, for a malicious purpose. ROPGuard defines a set of checks that can be used to detect when certain functions are being called in the context of malicious ROP code and can help protect against attacks exploiting memory safety vulnerabilities.
The BlueHat Prize competition, a program aimed at nurturing innovation in exploit mitigations through awarding more than $250,000 in cash and prizes, was launched by Microsoft one year ago at the Black Hat security conference in Las Vegas. The contest closed April 1, 2012, and the three finalists were named on June 21, 2012.
EMET Technology Preview 3.5 isavailable on the Microsoft download center.