Protecting C++ Dynamic Dispatch Through VTable Interleaving
Dimitar Bounov, Rami Gökhan Kici, Sorin Lerner
Abstract
With new defenses against traditional control-flow attacks like stack buffer overflows, attackers are increasingly using more advanced mechanisms to take control of execution. One common such attack is vtable hijacking, in which the attacker exploits bugs in C++ programs to overwrite pointers to the virtual method tables (vtables) of objects. We present a novel defense against this attack. The key insight of our approach is a new way of laying out vtables in memory through careful ordering and interleaving. Although this layout is very different from a traditional layout, it is backwards compatible with the traditional way of performing dynamic dispatch. Most importantly, with this new layout, checking the validity of a vtable at runtime becomes an efficient range check, rather than a set membership test. Compared to prior approaches that provide similar guarantees, our approach does not use any profiling information, has lower performance overhead (about 1%) and has lower code bloat overhead (about 1.7%). Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 88a96ce6-7b7c-493b-9a43-60ccd618f645Cited by top-tier papers12
- SoK: Shining Light on Shadow StacksNathan Burow, Xinping Zhang, Mathias PayerS&P 2019 · 170 citations
- HDFI: Hardware-Assisted Data-Flow IsolationChengyu Song, Hyungon Moon, Monjur Alam, Insu Yun et al.S&P 2016 · 146 citations
- TypeSan: Practical Type Confusion DetectionIstván Haller, Yuseok Jeon, Hui Peng, Mathias Payer et al.CCS 2016 · 97 citations
- CFIXX: Object Type Integrity for C++Nathan Burow, Derrick Paul McKee, Scott A. Carr, Mathias PayerNDSS 2018 · 56 citations
- CONFIRM: Evaluating Compatibility and Relevance of Control-flow Integrity Protections for Modern SoftwareXiaoyang Xu, Masoud Ghaffarinia, Wenhao Wang, Kevin W. Hamlen et al.USENIX Security 2019 · 49 citations
Related papers
- VTrust: Regaining Trust on Virtual CallsChao Zhang, Dawn Song, Scott A. Carr, Mathias Payer et al.NDSS 2016 · 91 citations
- PIBE: practical kernel control-flow hardening with profile-guided indirect branch eliminationVictor Duta, Cristiano Giuffrida, Herbert Bos, Erik van der KouweASPLOS 2021 · 12 citations
- Devil is Virtual: Reversing Virtual Inheritance in C++ BinariesRukayat Ayomide Erinfolami, Aravind PrakashCCS 2020
- type++: Prohibiting Type Confusion with Inline Type InformationNicolas Badoux, Flavio Toffalini, Yuseok Jeon, Mathias PayerNDSS 2025
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
