PeTAL: Ensuring Access Control Integrity against Data-only Attacks on Linux
Juhee Kim, Jinbum Park, Yoochan Lee, Chengyu Song, Taesoo Kim, Byoungyoung Lee
Abstract
Data-only attacks are emerging as a new threat to the security of modern operating systems. As a typical data-only attack, memory corruption attacks can compromise the integrity of kernel data, which effectively breaks the premises of access control systems. Unfortunately, the prevalence of memory corruption vulnerabilities allows attackers to exploit them and bypass access control mechanisms. Given the arbitrary memory access capability, attackers can overwrite access control policies or illegally access the kernel resources protected by the access control systems. This paper presents PeTAL, a practical access control integrity solution against data-only attacks on the ARM-based Linux kernel. PeTAL is designed to ensure access control integrity by providing policy integrity and complete enforcement of access control systems. PeTAL first identifies kernel data used as access control policies and kernel data protected by access control policies, based on the user interfaces of the Linux kernel. Then, PeTAL leverages the ARM Pointer Authentication Code (PAC) and Memory Tagging Extension (MTE) to comprehensively protect the integrity of the identified kernel data and pointers. We implemented the prototype of PeTAL and evaluated the performance and the security impact of PeTAL on real AArch64 hardware with PAC and MTE support. Our evaluation results show that PeTAL can effectively thwart memorycorruption-based attacks on access control systems with reasonable performance overheads at most 4% on average in user applications, demonstrating its efficient prospects for kernel security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c49705ad-59c9-403c-81f6-3d1b06758cb4Cited by top-tier papers6
- SpecASan: Mitigating Transient Execution Attacks Using Speculative Address SanitizationSaber Ganjisaffar, Esmaeil Mohmmadian Koruyeh, Jason Zellmer, Hodjat Asghari Esfeden et al.ISCA 2025 · 1 citation
- DirtyFree: Simplified Data-Oriented Programming in the Linux KernelYoochan Lee, Hyuk Kwon, Thorsten HolzNDSS 2026 · 1 citation
- NanoTag: Systems Support for Efficient Byte-Granular Overflow Detection on ARM MTEMingkai Li, Hang Ye, Joseph Devietti, Suman Jana et al.S&P 2026 · 1 citation
- Tide: An Efficient Kernel-level Isolation Execution Environment on AArch64 via Dynamically Adjusting Output Address SizeShiyang Zhang, Chenggang Wu, Chengxuan Hou, Jinglin Lv et al.CCS 2025
- IUBIK: Isolating User Bytes in Commodity Operating System Kernels via Memory Tagging ExtensionsMarius Momeu, Alexander J. Gaidis, Jasper v. d. Heidt, Vasileios P. KemerlisS&P 2025
Builds on28
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler et al.USENIX Security 2019 · 247 citations
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez et al.USENIX Security 2019 · 168 citations
Related papers
- Tiktag: Breaking ARM's Memory Tagging Extension with Speculative ExecutionJuhee Kim, Jinbum Park, Sihyeon Roh, Jaeyoung Chung et al.S&P 2025
- PTAuth: Temporal Memory Safety via Robust Points-to AuthenticationReza Mirzazade Farkhani, Mansour Ahmadi, Long LuUSENIX Security 2021 · 67 citations
- Camouflage: Hardware-assisted CFI for the ARM Linux kernelRémi Denis-Courmont, Hans Liljestrand, Carlos Chinea Perez, Jan-Erik EkbergDAC 2020 · 18 citations
- ZeRØ: Zero-Overhead Resilient Operation Under Pointer Integrity AttacksMohamed Tarek Ibn Ziad, Miguel A. Arroyo, Evgeny Manzhosov, Simha SethumadhavanISCA 2021 · 17 citations
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris et al.NDSS 2016 · 141 citations
