HardsHeap: A Universal and Extensible Framework for Evaluating Secure Allocators
Insu Yun, Woosun Song, Seunggi Min, Taesoo Kim
Abstract
Secure allocators have been extensively studied to mitigate heap vulnerabilities. They employ safe designs and randomized mechanisms to stop or mitigate heap exploitation. Despite extensive research efforts, secure allocators can only be evaluated by with theoretical analysis or pre-defined data sets, which are insufficient to effectively reflect powerful adversaries in the real world. In this paper, we present HardsHeap, an automatic tool for evaluating secure allocators. The key idea of HardsHeap is to use random testing (i.e., fuzzing) to evaluate secure allocators. To handle the diverse properties of secure allocators, HardsHeap supports an extensible framework, making it easy to write a validation logic for each property. Moreover, HardsHeap employs sampling-based testing, which enables us to evaluate a probabilistic mechanism prevalent in secure allocators. To eliminate redundancy in findings from HardsHeap, we devise a new technique called Statistical Significance Delta Debugging (SSDD), which extends the existing delta debugging for stochastically reproducible test cases. We evaluated HardsHeap to 10 secure allocators. Consequently, we found 56 interesting test cases, including several unsecure yet underestimated behaviors for handling large objects in secure allocators. Moreover, we discovered 10 implementation bugs. One of the bugs is integer overflow in secure allocators, making them even more invulnerable than ordinary allocators. Our evaluation also shows that SSDD successfully reduces test cases by 37.2% on average without a loss of reproducibility.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f34e6579-912e-41c9-9eb3-752e10e619f5Cited by top-tier papers3
- BUDAlloc: Defeating Use-After-Free Bugs by Decoupling Virtual Address Management from KernelJunho Ahn, Jaehyeon Lee, Kanghyuk Lee, Wooseok Gwak et al.USENIX Security 2024 · 6 citations
- StarMalloc: Verifying a Modern, Hardened Memory AllocatorAntonin Reitz, Aymeric Fromherz, Jonathan ProtzenkoOOPSLA 2024 · 5 citations
- Efficient Use-After-Free Prevention with Opportunistic Page-Level SweepingChanyoung Park, Hyungon MoonNDSS 2024
Builds on15
- FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free VulnerabilitiesWei Wu, Yueqi Chen, Jun Xu, Xinyu Xing et al.USENIX Security 2018 · 124 citations
- Poking Holes in Information HidingAngelos Oikonomopoulos, Elias Athanasopoulos, Herbert Bos, Cristiano GiuffridaUSENIX Security 2016 · 92 citations
- Revery: From Proof-of-Concept to ExploitableYan Wang, Chao Zhang, Xiaobo Xiang, Zixuan Zhao et al.CCS 2018 · 85 citations
- KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel VulnerabilitiesWei Wu, Yueqi Chen, Xinyu Xing, Wei ZouUSENIX Security 2019 · 75 citations
- FreeGuard: A Faster Secure Heap AllocatorSam Silvestro, Hongyu Liu, Corey Crosser, Zhiqiang Lin et al.CCS 2017 · 71 citations
Related papers
- Automatic Techniques to Systematically Discover New Heap Exploitation PrimitivesInsu Yun, Dhaval Kapil, Taesoo KimUSENIX Security 2020
- HeapHopper: Bringing Bounded Model Checking to Heap Implementation SecurityMoritz Eckert, Antonio Bianchi, Ruoyu Wang, Yan Shoshitaishvili et al.USENIX Security 2018 · 62 citations
- SeaK: Rethinking the Design of a Secure Allocator for OS KernelZicheng Wang, Yicheng Guang, Yueqi Chen, Zhenpeng Lin et al.USENIX Security 2024 · 1 citation
- Guarder: A Tunable Secure AllocatorSam Silvestro, Hongyu Liu, Tianyi Liu, Zhiqiang Lin et al.USENIX Security 2018 · 39 citations
- HEAPSTER: Analyzing the Security of Dynamic Allocators for Monolithic Firmware ImagesFabio Gritti, Fabio Pagani, Ilya Grishchenko, Lukas Dresel et al.S&P 2022 · 31 citations
