PtrSplit: Supporting General Pointers in Automatic Program Partitioning
Shen Liu, Gang Tan, Trent Jaeger
Abstract
Partitioning a security-sensitive application into least-privileged components and putting each into a separate protection domain have long been a goal of security practitioners and researchers. However, a stumbling block to automatically partitioning C/C++ applications is the presence of pointers in these applications. Pointers make calculating data dependence, a key step in program partitioning, difficult and hard to scale; furthermore, C/C++ pointers do not carry bounds information, making it impossible to automatically marshall and unmarshall pointer data when they are sent across the boundary of partitions. In this paper, we propose a set of techniques for supporting general pointers in automatic program partitioning. Our system, called PtrSplit, constructs a Program Dependence Graph (PDG) for tracking data and control dependencies in the input program and employs a parameter-tree approach for representing data of pointer types; this approach is modular and avoids global pointer analysis. Furthermore, it performs selective pointer bounds tracking to enable automatic marshalling/unmarshalling of pointer data, even when there is circularity and arbitrary aliasing. As a result, PtrSplit can automatically generate executable partitions for C applications that contain arbitrary pointers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers26
- Flightplan: Dataplane Disaggregation and Placement for P4 ProgramsNik Sultana, John Sonchack, Hans Giesen, Isaac Pedisich et al.NSDI 2021 · 95 citations
- DynPTA: Combining Static and Dynamic Analysis for Practical Selective Data ProtectionTapti Palit, Jarin Firose Moon, Fabian Monrose, Michalis PolychronakisS&P 2021 · 48 citations
- PKRU-safe: automatically locking down the heap between safe and unsafe languagesPaul Kirth, Mitchel Dickerson, Stephen Crane, Per Larsen et al.EuroSys 2022 · 41 citations
- FlexOS: towards flexible OS isolationHugo Lefeuvre, Vlad-Andrei Badoiu, Alexander Jung, Stefan Lucian Teodorescu et al.ASPLOS 2022 · 36 citations
- You shall not (by)pass!: practical, secure, and fast PKU-based sandboxingAlexios Voulimeneas, Jonas Vinck, Ruben Mechelinck, Stijn VolckaertEuroSys 2022 · 33 citations
Builds on1
Related papers
- Program-mandering: Quantitative Privilege SeparationShen Liu, Dongrui Zeng, Yongzhe Huang, Frank Capobianco et al.CCS 2019 · 30 citations
- Fast Flow-Sensitive C Program Partitioning via Iterative Value-Flow RefinementMaxwell Levatich, Stephen A. EdwardsICSE 2026
- Practical Program Modularization with Type-Based Dependence AnalysisKangjie LuS&P 2023
- KSplit: Automating Device Driver IsolationYongzhe Huang, Vikram Narayanan, David Detweiler, Kaiming Huang et al.OSDI 2022 · 26 citations
- Validating the Integrity of Audit Logs Against Execution Repartitioning AttacksCarter Yagemann, Mohammad A. Noureddine, Wajih Ul Hassan, Simon P. Chung et al.CCS 2021 · 17 citations
