USENIX Security2021Top-tier venue
ExpRace: Exploiting Kernel Races through Raising Interrupts
Yoochan Lee, Changwoo Min, Byoungyoung Lee
Abstract
A kernel data race is notoriously challenging to detect, reproduce, and diagnose, mainly caused by nondeterministic thread interleaving. The kernel data race has a critical security implication since it often leads to memory corruption, which can be abused to launch privilege escalation attacks. Interestingly, due to the challenges above, the exploitation of the kernel data race is also challenging. Specifically, we find that some kernel races are nearly impossible to exploit due to their unique requirement on execution orders, which are almost impossible to happen without manual intervention. This paper develops a generic exploitation technique for kernel data races. To this end, we first analyze kernel data races, which finds an intrinsic condition classifying easy-to-exploit and hard-to-exploit races. Then we develop EXPRACE, a generic race exploitation technique for modern kernels, including Linux, Microsoft Windows, and MAC OS X. EXPRACE turns hard-to-exploit races into easy-toexploit races by manipulating an interrupt mechanism during the exploitation. According to our evaluation with 10 realworld hard-to-exploit races, EXPRACE was able to exploit all of those within 10 to 118 seconds, while an exploitation without EXPRACE failed for all given 24 hours.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5ac6ed1b-4c29-423f-b93f-461b2ebc7301Cited by top-tier papers26
- HECKLER: Breaking Confidential VMs with Malicious InterruptsBenedict Schlüter, Supraja Sridhara, Mark Kuhne, Andrin Bertschi et al.USENIX Security 2024 · 48 citations
- HARDLOG: Practical Tamper-Proof System Auditing Using a Novel Audit DeviceAdil Ahmad, Sangho Lee, Marcus PeinadoS&P 2022 · 46 citations
- Snowboard: Finding Kernel Concurrency Bugs through Systematic Inter-thread Communication AnalysisSishuai Gong, Deniz Altinbüken, Pedro Fonseca, Petros ManiatisSOSP 2021 · 26 citations
- Userspace Bypass: Accelerating Syscall-intensive ApplicationsZhe Zhou, Yanxiang Bi, Junpeng Wan, Yangfan Zhou et al.OSDI 2023 · 18 citations
- SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux KernelLukas Maar, Stefan Gast, Martin Unterguggenberger, Mathias Oberhuber et al.USENIX Security 2024 · 16 citations
Builds on8
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee et al.S&P 2019 · 202 citations
- Breaking Kernel Address Space Layout Randomization with Intel TSXYeongjin Jang, Sangho Lee, Taesoo KimCCS 2016 · 174 citations
- Nemesis: Studying Microarchitectural Timing Leaks in Rudimentary CPU Interrupt LogicJo Van Bulck, Frank Piessens, Raoul StrackxCCS 2018 · 141 citations
- FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free VulnerabilitiesWei Wu, Yueqi Chen, Jun Xu, Xinyu Xing et al.USENIX Security 2018 · 124 citations
Related papers
- LR-Miner: Static Race Detection in OS Kernels by Mining Locking RulesTuo Li, Jia-Ju Bai, Gui-Dong Han, Shi-Min HuUSENIX Security 2024 · 6 citations
- Precise Detection of Kernel Data Races with Probabilistic Lockset AnalysisGabriel Ryan, Abhishek Shah, Dongdong She, Suman JanaS&P 2023
- GhostRace: Exploiting and Mitigating Speculative Race ConditionsHany Ragab, Andrea Mambretti, Anil Kurmus, Cristiano GiuffridaUSENIX Security 2024 · 10 citations
- SLAKE: Facilitating Slab Manipulation for Exploiting Vulnerabilities in the Linux KernelYueqi Chen, Xinyu XingCCS 2019 · 76 citations
- COMRace: Detecting Data Race Vulnerabilities in COM ObjectsFangming Gu, Qingli Guo, Lian Li, Zhiniang Peng et al.USENIX Security 2022
