IsolatOS: Detecting Double Fetch Bugs in COTS RTOS by Re-enabling Kernel Isolation
Yingjie Cao, Xiaogang Zhu, Dean Sullivan, Haowei Yang, Lei Xue, Xian Li, Chenxiong Qian, Minrui Yan, Xiapu Luo
摘要
—Real-time operating systems (RTOS) often expose double-fetch vulnerabilities when the kernel reads the same user-space memory location multiple times without ensuring consistency between fetches. Conventional static analysis cannot inspect proprietary, commercial off-the-shelf (COTS) RTOS kernels, and dynamic heuristics, which rely on broad time-window thresholds, suffer from high false positive rates and heavy emulation overhead. To address these challenges, we present ISOLAT OS, the first hardware-supported framework for detecting double-fetch bugs in COTS RTOS. By leveraging modern CPU kernel-isolation features, ISOLAT OS enables kernel isolation so that cross-boundary accesses can be captured by triggering page faults. ISOLAT OS then records page-fault metadata on each user-memory fetch. Finally, multiple fetches in the same system call are determined as a double-fetch bug, based on the lifecycle of system calls that ISOLAT OS instruments into COTS RTOS. We evaluate ISOLAT OS on three widely used RTOS, including QNX, VxWorks, and seL4, and demonstrate a 79.3 × reduction in runtime overhead compared to state-of-the-art emulation-based detectors. ISOLAT OS also detects double-fetch bugs with lower false positive rates than other tools. Our approach uncovers 43 previously unknown vulnerabilities in COTS RTOS (41 confirmed by vendors, 2 CVEs assigned). Additionally, we have demonstrated the real-world impact of our findings in automotive systems by exploiting them.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper10
- Precise and Scalable Detection of Double-Fetch Bugs in OS KernelsMeng Xu, Chenxiong Qian, Kangjie Lu, Michael Backes 等S&P 2018 · 被引用 95 次
- How Double-Fetch Situations turn into Double-Fetch Vulnerabilities: A Study of Double Fetches in the Linux KernelPengfei Wang, Jens Krinke, Kai Lu, Gen Li 等USENIX Security 2017 · 被引用 66 次
- SoK: Demystifying Binary Lifters Through the Lens of Downstream ApplicationsZhibo Liu, Yuanyuan Yuan, Shuai Wang, Yuyan BaoS&P 2022 · 被引用 29 次
- V-Shuttle: Scalable and Semantics-Aware Hypervisor Virtual Device FuzzingGaoning Pan, Xingwei Lin, Xuhong Zhang, Yongkang Jia 等CCS 2021 · 被引用 23 次
- SafeFetch: Practical Double-Fetch Protection with Kernel-Fetch CachingVictor Duta, Mitchel Aloserij, Cristiano GiuffridaUSENIX Security 2024 · 被引用 2 次
相关 Paper
- Midas: Systematic Kernel TOCTTOU ProtectionAtri Bhattacharyya, Uros Tesic, Mathias PayerUSENIX Security 2022
- LEMIX: Enabling Testing of Embedded Applications as Linux ApplicationsSai Ritvik Tanksalkar, Siddharth Muralee, Srihari Danduri, Paschal C. Amusuo 等USENIX Security 2025
- RTCON: Context-Adaptive Function-Level Fuzzing for RTOS KernelsEunkyu Lee, Junyoung Park, Insu YunNDSS 2026 · 被引用 1 次
- Interference-free Operating System: A 6 Years' Experience in Mitigating Cross-Core Interference in LinuxZhaomeng Deng, Ziqi Zhang, Ding Li, Yao Guo 等RTSS 2024 · 被引用 6 次
- TickTock: Verified Isolation in a Production Embedded OSVivien Rindisbacher, Evan Johnson, Nico Lehmann, Tyler Potyondy 等SOSP 2025
