USENIX Security2024Top-tier venue
RustSan: Retrofitting AddressSanitizer for Efficient Sanitization of Rust
Kyuwon Cho, Jongyoon Kim, Kha Dinh Duy, Hajeong Lim, Hojoon Lee
Abstract
Rust is gaining traction as a safe systems programming language with its strong type and memory safety guarantees. However, Rust's guarantees are not infallible. The use of unsafe Rust, a subvariant of Rust, allows the programmer to temporarily escape the strict Rust language semantics to trade security for flexibility. Memory errors within unsafe blocks in Rust have far-reaching ramifications for the program's safety. As a result, the conventional dynamic memory error detection (e.g., fuzzing) has been adapted as a common practice for Rust and proved its effectiveness through a trophy case of discovered CVEs. RUSTSAN is a retrofitted design of AddressSanitizer (ASan) for efficient dynamic memory error detection of Rust programs. Our observation is that a significant portion of instrumented memory access sites in a Rust program compiled with ASan is redundant, as the Rust security guarantees can still be valid at the site. RUSTSAN identifies and instruments the sites that definitely or may undermine Rust security guarantees while lifting instrumentation on safe sites. To this end, RUSTSAN employs a cross-IR program analysis for accurate tracking of unsafe sites and also extends ASan's shadow memory scheme for checking non-uniform memory access validation necessary for Rust. We conduct a comprehensive evaluation of RUSTSAN in terms of detection capability and performance using 57 Rust crates. RUSTSAN successfully detected all 31 tested cases of CVE-issued memory errors. Also, RUSTSAN shows an average of 62.3% performance increase against ASan in general benchmarks that involved 20 Rust crates. In the fuzzing experiment with 6 crates, RUST-SAN marked an average of 23.52%, and up to 57.08% of performance improvement. * Corresponding author strict compile-time rules and lightweight runtime checking. Many new developments have adopted Rust as the main programming language [2, 4-8, 17, 21, 41]. Also, the inclusion of Rust infrastructure in the Linux kernel [2] was a landmark in the ongoing widespread adoption of Rust. However, Rust's safety guarantees are not achieved without a price. Rust draws the programmer's cooperation by imposing its strict language semantics. By doing so, the language design and the programmer together yield code whose memory safety can be validated by the compiler and minimal runtime checks. Rust's safety model can be too restrictive for certain use cases requiring fine-grained touch. For this reason, Rust provides a variant of itself called unsafe Rust that lives within a code block declared using the unsafe keyword. The unsafe Rust enjoys unconfined access to language semantics prohibited in Rust, such as raw pointer access and bypassing strict ownership enforcement [9] . The use of unsafe can be inevitable in certain programs (e.g., interfacing with low-level components) or a programmer's choice to trade safety for flexibility. Previous works have studied the common practices regarding using unsafe in Rust and their ramifications of using unsafe in Rust programs [22, 56] . The findings in these works indicate that the use of unsafe Rust is nearly the sole source of memory errors in Rust programs [56] . In response, researchers have proposed static analysis for discovering unsafe Rust memory errors [14, 26, 36, 37] and runtime isolation of safe Rust from unsafe in Rust programs [15, 31, 33, 38, 45] . Static analysis methods have limited detection capability on highly complex bugs or those that reveal themselves during runtime. Runtime isolation frameworks have laid the foundation for identifying insecure program subsets of Rust programs to protect safe Rust parts. Runtime isolation contains the impact of, rather than detect, the memory errors that stem from unsafe Rust. In addition, the proposed isolation solutions accompany hardware feature dependency (e.g., Memory Protection Key (MPK)) [15, 31] that hinders portability. Efforts are being made towards revamping the existing techniques to secure Rust amid the rise of safe languages. An efficient and
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b4b4b8d6-37ea-4aa5-bf07-5ee6a493c1f8Cited by top-tier papers4
- deepSURF: Detecting Memory Safety Vulnerabilities in Rust Through Fuzzing LLM-Augmented HarnessesGeorgios C. Androutsopoulos, Antonio BianchiS&P 2026 · 5 citations
- Securing Mixed Rust with Hardware CapabilitiesJason Zhijingcheng Yu, Fangqi Han, Kaustab Choudhury, Trevor E. Carlson et al.CCS 2025 · 1 citation
- SafeFFI: Efficient Sanitization at the Boundary Between Safe and Unsafe Code in Rust and Mixed-Language ApplicationsOliver Braunsdorf, Tim Lange, Konrad Hohentanner, Julian Horsch et al.USENIX Security 2026
- CULPA: Universal Detection of Memory-Safety Bugs in Unsafe Rust Through the Lens of Safety RequirementsHung-Mao Chen, Bo Lu, Xu He, Xiaokuan Zhang et al.USENIX Security 2026
Builds on14
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee et al.S&P 2019 · 202 citations
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na et al.S&P 2019 · 196 citations
- RedLeaf: Isolation and Communication in a Safe Operating SystemVikram Narayanan, Tianjiao Huang, David Detweiler, Dan Appel et al.OSDI 2020 · 86 citations
- Theseus: an Experiment in Operating System Structure and State ManagementKevin Boos, Namitha Liyanage, Ramla Ijaz, Lin ZhongOSDI 2020 · 67 citations
- MirChecker: Detecting Bugs in Rust Programs via Static AnalysisZhuohua Li, Jincheng Wang, Mingshen Sun, John C. S. LuiCCS 2021 · 63 citations
Related papers
- ERASan: Efficient Rust Address SanitizerJiun Min, Dongyeon Yu, Seongyun Jeong, Dokyung Song et al.S&P 2024 · 6 citations
- How do programmers use unsafe rust?Vytautas Astrauskas, Christoph Matheja, Federico Poli, Peter Müller et al.OOPSLA 2020 · 78 citations
- Is rust used safely by software developers?Ana Nora Evans, Bradford Campbell, Mary Lou SoffaICSE 2020 · 57 citations
- "I wouldn't want my unsafe code to run my pacemaker": An Interview Study on the Use, Comprehension, and Perceived Risks of Unsafe RustSandra Höltervennhoff, Philip Klostermeyer, Noah Wöhler, Yasemin Acar et al.USENIX Security 2023
- Understanding memory and thread safety practices and issues in real-world Rust programsBoqin Qin, Yilun Chen, Zeming Yu, Linhai Song et al.PLDI 2020 · 112 citations
