Protecting the Stack with Metadata Policies and Tagged Hardware
Nick Roessler, André DeHon
Abstract
The program call stack is a major source of exploitable security vulnerabilities in low-level, unsafe languages like C. In conventional runtime implementations, the underlying stack data is exposed and unprotected, allowing programming errors to turn into security violations. In this work, we design novel metadata-tag based, stack-protection security policies for a general-purpose tagged architecture. Our policies specifically exploit the natural locality of dynamic program call graphs to achieve cacheability of the metadata rules that they require. Our simple Return Address Protection policy has a performance overhead of 1.2% but just protects return addresses. The two richer policies we present, Static Authorities and Depth Isolation, provide object-level protection for all stack objects. When enforcing memory safety, our Static Authorities policy has a performance overhead of 5.7% and our Depth Isolation policy has a performance overhead of 4.5%. When enforcing dataflow integrity (DFI), in which we only detect a violation when a corrupted value is read, our Static Authorities policy has a performance overhead of 3.6% and our Depth Isolation policy has a performance overhead of 2.4%. To characterize our policies, we provide a stack threat taxonomy and show which threats are prevented by both prior work protection mechanisms and our policies.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7cc5042e-89df-4856-a945-3e86ebb4b9e5Cited by top-tier papers8
- SoK: Shining Light on Shadow StacksNathan Burow, Xinping Zhang, Mathias PayerS&P 2019 · 170 citations
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez et al.USENIX Security 2019 · 168 citations
- PACStack: an Authenticated Call StackHans Liljestrand, Thomas Nyman, Lachlan J. Gunn, Jan-Erik Ekberg et al.USENIX Security 2021 · 63 citations
- Le temps des cerises: efficient temporal stack safety on capability machines using directed capabilitiesAïna Linn Georges, Alix Trieu, Lars BirkedalOOPSLA 2022 · 17 citations
- Cross-Language AttacksSamuel Mergendahl, Nathan Burow, Hamed OkhraviNDSS 2022
Builds on2
Related papers
- Control Flow and Pointer Integrity Enforcement in a Secure Tagged ArchitectureRavi Theja Gollapudi, Gokturk Yuksek, David Demicco, Matthew Cole et al.S&P 2023
- CCTAG: Configurable and Combinable Tagged ArchitectureZhanpeng Liu, Yi Rong, Chenyang Li, Wende Tan et al.NDSS 2025
- The Taming of the Stack: Isolating Stack Data from Memory ErrorsKaiming Huang, Yongzhe Huang, Mathias Payer, Zhiyun Qian et al.NDSS 2022
- COGENT: Adaptable Compiler Toolchain for Tagging RISC-V BinariesDavid B. Demicco, Matthew Cole, Gokturk Yuksek, Ravi Theja Gollapudi et al.ASPLOS 2025
- Silhouette: Efficient Protected Shadow Stacks for Embedded SystemsJie Zhou, Yufei Du, Zhuojia Shen, Lele Ma et al.USENIX Security 2020
