CFIXX: Object Type Integrity for C++
Nathan Burow, Derrick Paul McKee, Scott A. Carr, Mathias Payer
Abstract
C++ relies on object type information for dynamic dispatch and casting. The association of type information to an object is implemented via the virtual table pointer, which is stored in the object itself. As C++ has neither memory nor type safety, adversaries may therefore overwrite an object's type. If the corrupted type is used for dynamic dispatch, the attacker has hijacked the application's control flow. This vulnerability is widespread and commonly exploited. Firefox, Chrome, and other major C++ applications are network facing, commonly attacked, and make significant use of dynamic dispatch. Control-Flow Integrity (CFI) is the state of the art policy for efficient mitigation of control-flow hijacking attacks. CFI mechanisms determine statically (i.e., at compile time) the set of functions that are valid at a given call site, based on C++ semantics. We propose an orthogonal policy, Object Type Integrity (OTI), that dynamically tracks object types. Consequently, instead of allowing a set of targets for each dynamic dispatch on an object, only the single, correct target for the object's type is allowed. To show the efficacy of OTI, we present CFIXX, which enforces OTI. CFIXX enforces OTI by dynamically tracking the type of each object and enforcing its integrity against arbitrary writes. CFIXX has minimal overhead on CPU bound applications such as SPEC CPU2006 -4.98%. On key applications like Chromium, CFIXX has negligible overhead on JavaScript benchmarks: 2.03% on Octane, 1.99% on Kraken, and 2.80% on JetStream. We show that CFIXX can be deployed in conjunction with CFI, providing a significant security improvement.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2ada9a3b-71d9-4530-ab06-25da0a7b822aCited by top-tier papers6
- Origin-sensitive Control Flow IntegrityMustakimur Khandaker, Wenqing Liu, Abu Naser, Zhi Wang et al.USENIX Security 2019 · 71 citations
- CONFIRM: Evaluating Compatibility and Relevance of Control-flow Integrity Protections for Modern SoftwareXiaoyang Xu, Masoud Ghaffarinia, Wenhao Wang, Kevin W. Hamlen et al.USENIX Security 2019 · 49 citations
- SafeHidden: An Efficient and Secure Information Hiding Technique Using Re-randomizationZhe Wang, Chenggang Wu, Yinqian Zhang, Bowen Tang et al.USENIX Security 2019 · 18 citations
- Top of the Heap: Efficient Memory Error Protection of Safe Heap ObjectsKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson et al.CCS 2024 · 3 citations
- Link-Time Optimization of Dynamic Casts in C++ ProgramsXufan Lu, Nuno P. LopesPLDI 2025 · 1 citation
Builds on6
- ASLR on the Line: Practical Cache Attacks on the MMUBen Gras, Kaveh Razavi, Erik Bosman, Herbert Bos et al.NDSS 2017 · 276 citations
- Efficient Protection of Path-Sensitive Control SecurityRen Ding, Chenxiong Qian, Chengyu Song, William Harris et al.USENIX Security 2017 · 123 citations
- Stack Bounds Protection with Low Fat PointersGregory J. Duck, Roland H. C. Yap, Lorenzo CavallaroNDSS 2017 · 121 citations
- TypeSan: Practical Type Confusion DetectionIstván Haller, Yuseok Jeon, Hui Peng, Mathias Payer et al.CCS 2016 · 97 citations
- VTrust: Regaining Trust on Virtual CallsChao Zhang, Dawn Song, Scott A. Carr, Mathias Payer et al.NDSS 2016 · 91 citations
Related papers
- HexType: Efficient Detection of Type Confusion Errors for C++Yuseok Jeon, Priyam Biswas, Scott A. Carr, Byoungyoung Lee et al.CCS 2017 · 67 citations
- type++: Prohibiting Type Confusion with Inline Type InformationNicolas Badoux, Flavio Toffalini, Yuseok Jeon, Mathias PayerNDSS 2025
- Finding Cracks in Shields: On the Security of Control Flow Integrity MechanismsYuan Li, Mingzhe Wang, Chao Zhang, Xingman Chen et al.CCS 2020 · 32 citations
- VScape: Assessing and Escaping Virtual Call ProtectionsKaixiang Chen, Chao Zhang, Tingting Yin, Xingman Chen et al.USENIX Security 2021 · 5 citations
- Enforcing C/C++ Type and Scope at Runtime for Control-Flow and Data-Flow IntegrityMohannad Ismail, Christopher Jelesnianski, Yeongjin Jang, Changwoo Min et al.ASPLOS 2024 · 3 citations
