A Robust and Efficient Defense against Use-after-Free Exploits via Concurrent Pointer Sweeping
Daiping Liu, Mingwei Zhang, Haining Wang
Abstract
Applications in C/C++ are notoriously prone to memory corruptions. With significant research efforts devoted to this area of study, the security threats posed by previously popular vulnerabilities, such as stack and heap overflows, are not as serious as before. Instead, we have seen the meteoric rise of attacks exploiting use-afterfree (UaF) vulnerabilities in recent years, which root in pointers pointing to freed memory (i.e., dangling pointers). Although various approaches have been proposed to harden software against UaF, none of them can achieve robustness and efficiency at the same time. In this paper, we present a novel defense called pSweeper to robustly protect against UaF exploits with low overhead, and pinpoint the root-causes of UaF vulnerabilities with one safe crash. The success of pSweeper lies in its two unique and innovative design ideas, concurrent pointer sweeping (CPW) and object origin tracking (OOT). CPW exploits the increasingly available multicores on modern PCs and outsources the heavyweight security checks and enforcement to dedicated threads that can run on spare cores. Specifically, CPW iteratively sweeps all live pointers in a concurrent thread to find dangling pointers. This design is quite different from previous work that requires to track every pointer propagation to maintain accurate point-to relationship between pointers and objects. OOT can help to pinpoint the root-causes of UaF by informing developers of how a dangling pointer is created. We implement a prototype of pSweeper and validate its efficacy in real scenarios. Our experimental results show that pSweeper is effective in defeating real-world UaF exploits and efficient when deployed in production runs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1e7e59e7-3ae7-47bd-b40a-541e43c852e5Cited by top-tier papers19
- Cornucopia: Temporal Safety for CHERI HeapsNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Sam Ainsworth et al.S&P 2020 · 71 citations
- PTAuth: Temporal Memory Safety via Robust Points-to AuthenticationReza Mirzazade Farkhani, Mansour Ahmadi, Long LuUSENIX Security 2021 · 67 citations
- MarkUs: Drop-in use-after-free prevention for low-level languagesSam Ainsworth, Timothy M. JonesS&P 2020 · 63 citations
- Preventing Use-After-Free Attacks with Fast Forward AllocationBrian Wickman, Hong Hu, Insu Yun, Daehee Jang et al.USENIX Security 2021 · 53 citations
- Cryptographic Capability ComputingMichael LeMay, Joydeep Rakshit, Sergej Deutsch, David M. Durham et al.MICRO 2021 · 29 citations
Related papers
- MineSweeper: a "clean sweep" for drop-in use-after-free preventionMárton Erdos, Sam Ainsworth, Timothy M. JonesASPLOS 2022 · 13 citations
- SwiftSweeper: Defeating Use-After-Free Bugs Using Memory Sweeper Without Stop-the-WorldJunho Ahn, Kanghyuk Lee, Chanyoung Park, Hyungon Moon et al.S&P 2025
- UAFSan: an object-identifier-based dynamic approach for detecting use-after-free vulnerabilitiesBinfa Gui, Wei Song, Jeff HuangISSTA 2021 · 9 citations
- FreeWill: Automatically Diagnosing Use-after-free Bugs via Reference Miscounting Detection on BinariesLiang He, Hong Hu, Purui Su, Yan Cai et al.USENIX Security 2022
- Fast Pointer Nullification for Use-After-Free PreventionYubo Du, Youtao Zhang, Jun YangNDSS 2026
