USENIX Security2023Top-tier venue
MTSan: A Feasible and Practical Memory Sanitizer for Fuzzing COTS Binaries
Xingman Chen, Yinghao Shi, Zheyu Jiang, Yuan Li, Ruoyu Wang, Haixin Duan, Haoyu Wang, Chao Zhang
Abstract
Fuzzing has been widely adopted for finding vulnerabilities in programs, especially when source code is not available. But the effectiveness and efficiency of binary fuzzing are curtailed by the lack of memory (safety) sanitizers. This lack of binary sanitizers is due to the information loss in compiling programs and challenges in binary instrumentation. In this paper, we present a feasible and practical hardwareassisted memory sanitizer, MTSan, for binary fuzzing. MT-San can detect both spatial and temporal memory safety violations at runtime. It adopts a novel progressive object recovery scheme to recover objects in binaries, and uses a customized binary rewriting solution to instrument binaries with the memory-tagging-based memory safety sanitizing policy. Further, MTSan uses a hardware feature, ARM Memory Tagging Extension (MTE) to significantly reduce its runtime overhead. We implemented a prototype of MT-San on AArch64 and systematically evaluated its effectiveness and performance. Our evaluation results show that MT-San could detect more memory safety violations than existing binary sanitizers whiling introducing much lower runtime and memory overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9e1d534d-88c1-43aa-a2e4-aa966fec26b1Cited by top-tier papers10
- Sticky Tags: Efficient and Deterministic Spatial Memory Error Mitigation using Persistent Memory TagsFloris Gorter, Taddeus Kroes, Herbert Bos, Cristiano GiuffridaS&P 2024 · 22 citations
- A Binary-level Thread Sanitizer or Why Sanitizing on the Binary Level is HardJoschua Schilling, Andreas Wendler, Philipp Görz, Nils Bars et al.USENIX Security 2024 · 4 citations
- NanoTag: Systems Support for Efficient Byte-Granular Overflow Detection on ARM MTEMingkai Li, Hang Ye, Joseph Devietti, Suman Jana et al.S&P 2026 · 1 citation
- QuickSafe: Targeted Hardening Against Memory CorruptionJohannes Blaser, Floris Gorter, Klaus von Gleissenthall, Herbert BosS&P 2026
- QMSan: Efficiently Detecting Uninitialized Memory Errors During FuzzingMatteo Marini, Daniele Cono D'Elia, Mathias Payer, Leonardo QuerzoniNDSS 2025
Builds on17
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- T-Fuzz: Fuzzing by Program TransformationHui Peng, Yan Shoshitaishvili, Mathias PayerS&P 2018 · 326 citations
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na et al.S&P 2019 · 196 citations
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 187 citations
Related papers
- RangeSanitizer: Detecting Memory Errors with Efficient Range ChecksFloris Gorter, Cristiano GiuffridaUSENIX Security 2025
- SpecASan: Mitigating Transient Execution Attacks Using Speculative Address SanitizationSaber Ganjisaffar, Esmaeil Mohmmadian Koruyeh, Jason Zellmer, Hodjat Asghari Esfeden et al.ISCA 2025 · 1 citation
- PACMem: Enforcing Spatial and Temporal Memory Safety via ARM Pointer AuthenticationYuan Li, Wende Tan, Zhizheng Lv, Songtao Yang et al.CCS 2022 · 30 citations
- Tiktag: Breaking ARM's Memory Tagging Extension with Speculative ExecutionJuhee Kim, Jinbum Park, Sihyeon Roh, Jaeyoung Chung et al.S&P 2025
- BASTAG: Byte-level Access Control on Shared Memory using ARM Memory Tagging ExtensionJunseung You, Jiwon Seo, Kyeongryong Lee, Yeongpil Cho et al.CCS 2025
