arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

量子ROP:在漏洞利用构造中使用量子算法进行ROP链选择

Quantum ROP: Using Quantum Algorithms for ROP Chain Selection in Exploit Construction

Carlos Benitez

arXiv 2609.25364首次发表:更新:

发表机构

PLATINUM CIBER(Platinum Ciber)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究将量子组合优化应用于ROP小工具选择,提出QUBO建模并用QAOA在IBM Heron r2硬件上求解,在Linux内核场景实现提权,多数基准实例中找到最优链。

AI 中文摘要

量子计算对网络安全的威胁如今主要围绕Shor算法及其最终破解非对称密码学的能力来讨论。然而,除了密码分析之外,量子计算还可能为进攻性安全带来其他能力。本研究探索了其中一个方向:将量子组合优化应用于面向返回编程(ROP)小工具选择,以构造漏洞利用。我们将小工具选择建模为一个二次无约束二元优化(QUBO)问题,该问题捕获单个小工具成本以及小工具间寄存器破坏交互,并使用QAOA在真实的IBM Heron r2硬件上求解。应用于Linux内核漏洞利用场景时,QAOA选择的链在SMEP和SMAP激活的情况下实现了提权至uid=0。在八个Linux二进制文件和16个基准实例中,QAOA在11个案例中恢复了最低成本的有效链;在其余五个案例中,它未恢复最优解,失败与当前有限硬件上的过度电路深度相关。

英文摘要

The quantum computing threat to cybersecurity is nowadays predominantly framed around Shor's algorithm and its eventual capacity to break asymmetric cryptography. Beyond cryptanalysis, however, quantum computing may also enable other capabilities in offensive security. This work explores one such direction: the application of quantum combinatorial optimization to Return-Oriented Programming (ROP) gadget selection for exploit construction. We formulate gadget selection as a Quadratic Unconstrained Binary Optimization (QUBO) problem that captures individual gadget cost and inter-gadget register-clobbering interactions, and solve it using QAOA on real IBM Heron r2 hardware. Applied to a Linux kernel exploitation scenario, the QAOA-selected chain achieves privilege escalation to uid=0 with SMEP and SMAP active. Across eight Linux binaries and 16 benchmark instances, QAOA recovered the lowest-cost valid chain in 11 cases; in the remaining five, it did not recover the optimum, with the failures associated with excessive circuit depth on current limited hardware.

Comments29 pages, 3 figures

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑