Stack Bounds Protection with Low Fat Pointers
Gregory J. Duck, Roland H. C. Yap, Lorenzo Cavallaro
Abstract
Object bounds overflow errors are a common source of security vulnerabilities. In principle, bounds check instrumentation eliminates the problem, but this introduces high overheads and is further hampered by limited compatibility against un-instrumented code. On 64-bit systems, low-fat pointers are a recent scheme for implementing efficient and compatible bounds checking by transparently encoding meta information within the native pointer representation itself. However, low-fat pointers are traditionally used for heap objects only, where the allocator has sufficient control over object location necessary for the encoding. This is a problem for stack allocation, where there exist strong constraints regarding the location of stack objects that is apparently incompatible with the low-fat pointer approach. To address this problem, we present an extension of low-fat pointers to stack objects by using a collection of techniques, such as pointer mirroring and memory aliasing, thereby allowing stack objects to enjoy bounds error protection from instrumented code. Our extension is compatible with common special uses of the stack, such as alloca, setjmp and longjmp, exceptions, and multi-threading, which rely on direct manipulation of the stack pointer. Our experiments show that we successfully extend the advantages of the low-fat pointer encoding to stack objects. The end result is a competitive bounds checking instrumentation for the stack and heap with low memory and runtime overheads, and high compatibility with un-instrumented legacy code.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9dacd1b4-4d5e-49d3-b7c7-9e14725f927eCited by top-tier papers35
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na et al.S&P 2019 · 196 citations
- PtrSplit: Supporting General Pointers in Automatic Program PartitioningShen Liu, Gang Tan, Trent JaegerCCS 2017 · 83 citations
- Binary rewriting without control flow recoveryGregory J. Duck, Xiang Gao, Abhik RoychoudhuryPLDI 2020 · 77 citations
- CFIXX: Object Type Integrity for C++Nathan Burow, Derrick Paul McKee, Scott A. Carr, Mathias PayerNDSS 2018 · 56 citations
- Towards Efficient Heap Overflow DiscoveryXiangkun Jia, Chao Zhang, Purui Su, Yi Yang et al.USENIX Security 2017 · 36 citations
Builds on1
Related papers
- In-fat pointer: hardware-assisted tagged-pointer spatial memory safety defense with subobject granularity protectionShengjie Xu, Wei Huang, David LieASPLOS 2021 · 26 citations
- Look Before You Access: Efficient Heap Memory Safety for Embedded Systems on ARMv8-MJeonghwan Kang, Jaeyeol Park, Jiwon Seo, Donghyun KwonDAC 2024 · 1 citation
- No-FAT: Architectural Support for Low Overhead Memory Safety ChecksMohamed Tarek Ibn Ziad, Miguel A. Arroyo, Evgeny Manzhosov, Ryan Piersma et al.ISCA 2021 · 26 citations
- Fat Pointers for Temporal Memory Safety of CJie Zhou, John Criswell, Michael HicksOOPSLA 2023 · 17 citations
- Hardening binaries against more memory errorsGregory J. Duck, Yuntong Zhang, Roland H. C. YapEuroSys 2022 · 7 citations
