In-fat pointer: hardware-assisted tagged-pointer spatial memory safety defense with subobject granularity protection
Shengjie Xu, Wei Huang, David Lie
Abstract
Programming languages like C and C++ are not memory-safe because they provide programmers with low-level pointer manipulation primitives. The incorrect use of these primitives can result in bugs and security vulnerabilities: for example, spatial memory safety errors can be caused by dereferencing pointers outside the legitimate address range belonging to the corresponding object. While a range of schemes to provide protection against these vulnerabilities have been proposed, they all suffer from the lack of one or more of low performance overhead, compatibility with legacy code, or comprehensive protection for all objects and subobjects.
We present In-Fat Pointer, the first hardware-assisted defense that can achieve spatial memory safety at subobject granularity while maintaining compatibility with legacy code and low overhead. In-Fat Pointer improves the protection granularity of taggedpointer schemes using object metadata, which is efficient and binarycompatible for object-bound spatial safety. Unlike previous work that devotes all pointer tag bits to object metadata lookup, In-Fat Pointer uses three complementary object metadata schemes to reduce the number pointer tag bits needed for metadata lookup, allowing it to use the left-over bits, along with in-memory type metadata, to refine the object bounds to subobject granularity. We show that this approach provides practical protection of fine-grained spatial memory safety.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers13
- PACMem: Enforcing Spatial and Temporal Memory Safety via ARM Pointer AuthenticationYuan Li, Wende Tan, Zhizheng Lv, Songtao Yang et al.CCS 2022 · 30 citations
- No-FAT: Architectural Support for Low Overhead Memory Safety ChecksMohamed Tarek Ibn Ziad, Miguel A. Arroyo, Evgeny Manzhosov, Ryan Piersma et al.ISCA 2021 · 26 citations
- Securing GPU via region-based bounds checkingJaewon Lee, Yonghae Kim, Jiashen Cao, Euna Kim et al.ISCA 2022 · 19 citations
- TAILCHECK: A Lightweight Heap Overflow Detection Mechanism with Page Protection and Tagged PointersAmogha Udupa Shankaranarayana Gopal, Raveendra Soori, Michael Ferdman, Dongyoon LeeOSDI 2023 · 14 citations
- CAMP: Compiler and Allocator-based Heap Memory ProtectionZhenpeng Lin, Zheng Yu, Ziyi Guo, Simone Campanoni et al.USENIX Security 2024 · 14 citations
Builds on5
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na et al.S&P 2019 · 196 citations
- Stack Bounds Protection with Low Fat PointersGregory J. Duck, Roland H. C. Yap, Lorenzo CavallaroNDSS 2017 · 121 citations
- Hardware-based Always-On Heap Memory SafetyYonghae Kim, Jaekyu Lee, Hyesoon KimMICRO 2020 · 41 citations
- Prober: Practically Defending Overflows with Page ProtectionHongyu Liu, Ruiqin Tian, Tongping Liu, Bin RenASE 2020 · 3 citations
Related papers
- Look Before You Access: Efficient Heap Memory Safety for Embedded Systems on ARMv8-MJeonghwan Kang, Jaeyeol Park, Jiwon Seo, Donghyun KwonDAC 2024 · 1 citation
- Cryptographically Enforced Memory SafetyMartin Unterguggenberger, David Schrammel, Lukas Lamster, Pascal Nasahl et al.CCS 2023 · 6 citations
- Fat Pointers for Temporal Memory Safety of CJie Zhou, John Criswell, Michael HicksOOPSLA 2023 · 17 citations
- Cryptographic Capability ComputingMichael LeMay, Joydeep Rakshit, Sergej Deutsch, David M. Durham et al.MICRO 2021 · 29 citations
- CGuard: Scalable and Precise Object Bounds Protection for CPiyus Kedia, Rahul Purandare, Udit Kumar Agarwal, RishabhISSTA 2023 · 1 citation
