TypeSan: Practical Type Confusion Detection
István Haller, Yuseok Jeon, Hui Peng, Mathias Payer, Cristiano Giuffrida, Herbert Bos, Erik van der Kouwe
Abstract
The low-level C++ programming language is ubiquitously used for its modularity and performance. Typecasting is a fundamental concept in C++ (and object-oriented programming in general) to convert a pointer from one object type into another. However, downcasting (converting a base class pointer to a derived class pointer) has critical security implications due to potentially different object memory layouts. Due to missing type safety in C++, a downcasted pointer can violate a programmer's intended pointer semantics, allowing an attacker to corrupt the underlying memory in a type-unsafe fashion. This vulnerability class is receiving increasing attention and is known as type confusion (or badcasting). Several existing approaches detect different forms of type confusion, but these solutions are severely limited due to both high run-time performance overhead and low detection coverage. This paper presents TypeSan, a practical type-confusion detector which provides both low run-time overhead and high detection coverage. Despite improving the coverage of state-of-the-art techniques, TypeSan significantly reduces the type-confusion detection overhead compared to other solutions. TypeSan relies on an efficient per-object metadata storage service based on a compact memory shadowing scheme. Our scheme treats all the memory objects (i.e., globals, stack, heap) uniformly to eliminate extra checks on the fast path and relies on a variable compression ratio to minimize run-time performance and memory overhead. Our experimental results confirm that TypeSan is practical, even when explicitly checking almost all the relevant typecasts in a given C++ program. Compared to the state of the art, TypeSan yields orders of magnitude higher coverage at 4-10 times lower performance overhead on SPEC and 2 times on Firefox. As a result, our solution offers superior protec-
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d84fbedf-f7bf-43fe-82e7-e147d1d7f2deCited by top-tier papers35
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 836 citations
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na et al.S&P 2019 · 196 citations
- Enforcing Unique Code Target Property for Control-Flow IntegrityHong Hu, Chenxiong Qian, Carter Yagemann, Simon Pak Ho Chung et al.CCS 2018 · 142 citations
- Regression Greybox FuzzingXiaogang Zhu, Marcel BöhmeCCS 2021 · 84 citations
- HexType: Efficient Detection of Type Confusion Errors for C++Yuseok Jeon, Priyam Biswas, Scott A. Carr, Byoungyoung Lee et al.CCS 2017 · 67 citations
Builds on5
- A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary LevelVictor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski et al.S&P 2016 · 227 citations
- Poking Holes in Information HidingAngelos Oikonomopoulos, Elias Athanasopoulos, Herbert Bos, Cristiano GiuffridaUSENIX Security 2016 · 92 citations
- VTrust: Regaining Trust on Virtual CallsChao Zhang, Dawn Song, Scott A. Carr, Mathias Payer et al.NDSS 2016 · 91 citations
- Undermining Information Hiding (and What to Do about It)Enes Göktas, Robert Gawlik, Benjamin Kollenda, Elias Athanasopoulos et al.USENIX Security 2016 · 82 citations
- Protecting C++ Dynamic Dispatch Through VTable InterleavingDimitar Bounov, Rami Gökhan Kici, Sorin LernerNDSS 2016 · 77 citations
Related papers
- type++: Prohibiting Type Confusion with Inline Type InformationNicolas Badoux, Flavio Toffalini, Yuseok Jeon, Mathias PayerNDSS 2025
- Don't Waste My Efforts: Pruning Redundant Sanitizer Checks by Developer-Implemented Type ChecksYizhuo Zhai, Zhiyun Qian, Chengyu Song, Manu Sridharan et al.USENIX Security 2024 · 8 citations
- Uncontained: Uncovering Container Confusion in the Linux KernelJakob Koschel, Pietro Borrello, Daniele Cono D'Elia, Herbert Bos et al.USENIX Security 2023
- BSan: A Powerful Identifier-Based Hardware-Independent Memory Error Detector for COTS BinariesWen Zhang, Botang Xiao, Qingchen Kong, Le Guan et al.ICSE 2025
- Rusted Types: Static Detection of Rust Type Confusion BugsZeyang Zhuang, Wei Meng, Michael R. LyuICSE 2026
