Enhancing Memory Error Detection for Large-Scale Applications and Fuzz Testing
Wookhyun Han, Byunggill Joe, Byoungyoung Lee, Chengyu Song, Insik Shin
Abstract
Memory errors are one of the most common vulnerabilities for the popularity of memory unsafe languages including C and C++. Once exploited, it can easily lead to system crash (i.e., denial-of-service attacks) or allow adversaries to fully compromise the victim system. This paper proposes MEDS, a practical memory error detector. MEDS significantly enhances its detection capability by approximating two ideal properties, called an infinite gap and an infinite heap. The approximated infinite gap of MEDS setups large inaccessible memory region between objects (i.e., 4 MB), and the approximated infinite heap allows MEDS to fully utilize virtual address space (i.e., 45-bits memory space). The key idea of MEDS in achieving these properties is a novel user-space memory allocation mechanism, MEDSALLOC. MEDSALLOC leverages a page aliasing mechanism, which allows MEDS to maximize the virtual memory space utilization but minimize the physical memory uses. To highlight the detection capability and practical impacts of MEDS, we evaluated and then compared to Google's state-of-the-art detection tool, Ad-dressSanitizer. MEDS showed three times better detection rates on four real-world vulnerabilities in Chrome and Firefox. More importantly, when used for a fuzz testing, MEDS was able to identify 68.3% more memory errors than AddressSanitizer for the same amount of a testing time, highlighting its practical aspects in the software testing area. In terms of performance overhead, MEDS slowed down 108% and 86% compared to native execution and AddressSanitizer, respectively, on real-world applications including Chrome, Firefox, Apache, Nginx, and OpenSSL.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 304f4f09-5266-4500-bdd0-98ceee7458b7Cited by top-tier papers15
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik et al.NDSS 2019 · 413 citations
- PACMem: Enforcing Spatial and Temporal Memory Safety via ARM Pointer AuthenticationYuan Li, Wende Tan, Zhizheng Lv, Songtao Yang et al.CCS 2022 · 30 citations
- Sticky Tags: Efficient and Deterministic Spatial Memory Error Mitigation using Persistent Memory TagsFloris Gorter, Taddeus Kroes, Herbert Bos, Cristiano GiuffridaS&P 2024 · 22 citations
- Kard: lightweight data race detection with per-thread memory protectionAdil Ahmad, Sangho Lee, Pedro Fonseca, Byoungyoung LeeASPLOS 2021 · 17 citations
Builds on3
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- Stack Bounds Protection with Low Fat PointersGregory J. Duck, Roland H. C. Yap, Lorenzo CavallaroNDSS 2017 · 121 citations
- VTrust: Regaining Trust on Virtual CallsChao Zhang, Dawn Song, Scott A. Carr, Mathias Payer et al.NDSS 2016 · 91 citations
Related papers
- Evaluating the Effectiveness of Memory Safety SanitizersEmanuel Q. Vintila, Philipp Zieris, Julian HorschS&P 2025
- Debloating Address SanitizerYuchen Zhang, Chengbin Pang, Georgios Portokalidis, Nikos Triandopoulos et al.USENIX Security 2022
- FloatZone: Accelerating Memory Error Detection using the Floating Point UnitFloris Gorter, Enrico Barberis, Raphael Isemann, Erik van der Kouwe et al.USENIX Security 2023
- QuickSafe: Targeted Hardening Against Memory CorruptionJohannes Blaser, Floris Gorter, Klaus von Gleissenthall, Herbert BosS&P 2026
- CMASan: Custom Memory Allocator-aware Address SanitizerJunwha Hong, Wonil Jang, Mijung Kim, Lei Yu et al.S&P 2025
