Preventing Use-After-Free Attacks with Fast Forward Allocation
Brian Wickman, Hong Hu, Insu Yun, Daehee Jang, Jungwon Lim, Sanidhya Kashyap, Taesoo Kim
摘要
Memory-unsafe languages are widely used to implement critical systems like kernels and browsers, leading to thousands of memory safety issues every year. A use-after-free bug is a temporal memory error where the program accidentally visits a freed memory location. Recent studies show that useafter-free is one of the most exploited memory vulnerabilities. Unfortunately, previous efforts to mitigate use-after-free bugs are not widely deployed in real-world programs due to either inadequate accuracy or high performance overhead. In this paper, we propose to resurrect the idea of one-time allocation (OTA) and provide a practical implementation with efficient execution and moderate memory overhead. With onetime allocation, the memory manager always returns a distinct memory address for each request. Since memory locations are not reused, attackers cannot reclaim freed objects, and thus cannot exploit use-after-free bugs. We utilize two techniques to render OTA practical: batch page management and the fusion of bump-pointer and fixed-size bins memory allocation styles. Batch page management helps reduce the number of system calls which negatively impact performance, while blending the two allocation methods mitigates the memory overhead and fragmentation issues. We implemented a prototype, called FFmalloc, to demonstrate our techniques. We evaluated FFmalloc on widely used benchmarks and real-world large programs. FFmalloc successfully blocked all tested useafter-free attacks while introducing moderate overhead. The results show that OTA can be a strong and practical solution to thwart use-after-free threats.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper26
- Sticky Tags: Efficient and Deterministic Spatial Memory Error Mitigation using Persistent Memory TagsFloris Gorter, Taddeus Kroes, Herbert Bos, Cristiano GiuffridaS&P 2024 · 被引用 22 次
- Fat Pointers for Temporal Memory Safety of CJie Zhou, John Criswell, Michael HicksOOPSLA 2023 · 被引用 17 次
- Mitigating Information Leakage Vulnerabilities with Type-based Data IsolationAlyssa Milburn, Erik van der Kouwe, Cristiano GiuffridaS&P 2022 · 被引用 16 次
- CAMP: Compiler and Allocator-based Heap Memory ProtectionZhenpeng Lin, Zheng Yu, Ziyi Guo, Simone Campanoni 等USENIX Security 2024 · 被引用 14 次
- ShadowBound: Efficient Heap Memory Protection Through Advanced Metadata Management and Customized Compiler OptimizationZheng Yu, Ganxiang Yang, Xinyu XingUSENIX Security 2024 · 被引用 13 次
它引用的顶会 Paper7
- Oscar: A Practical Page-Permissions-Based Scheme for Thwarting Dangling PointersThurston H. Y. Dang, Petros Maniatis, David A. WagnerUSENIX Security 2017 · 被引用 77 次
- FreeGuard: A Faster Secure Heap AllocatorSam Silvestro, Hongyu Liu, Corey Crosser, Zhiqiang Lin 等CCS 2017 · 被引用 71 次
- MarkUs: Drop-in use-after-free prevention for low-level languagesSam Ainsworth, Timothy M. JonesS&P 2020 · 被引用 63 次
- A Robust and Efficient Defense against Use-after-Free Exploits via Concurrent Pointer SweepingDaiping Liu, Mingwei Zhang, Haining WangCCS 2018 · 被引用 43 次
- Guarder: A Tunable Secure AllocatorSam Silvestro, Hongyu Liu, Tianyi Liu, Zhiqiang Lin 等USENIX Security 2018 · 被引用 39 次
相关 Paper
- BUDAlloc: Defeating Use-After-Free Bugs by Decoupling Virtual Address Management from KernelJunho Ahn, Jaehyeon Lee, Kanghyuk Lee, Wooseok Gwak 等USENIX Security 2024 · 被引用 6 次
- PUMM: Preventing Use-After-Free Using Execution Unit PartitioningCarter Yagemann, Simon P. Chung, Brendan Saltaformaggio, Wenke LeeUSENIX Security 2023
- SeMalloc: Semantics-Informed Memory AllocatorRuizhe Wang, Meng Xu, N. AsokanCCS 2024
- MineSweeper: a "clean sweep" for drop-in use-after-free preventionMárton Erdos, Sam Ainsworth, Timothy M. JonesASPLOS 2022 · 被引用 13 次
- DMGuard: Safeguarding Kernels from Physical-Page Use-After-Free VulnerabilitiesJuhee Kim, Jaeyoung Chung, Dae R. Jeong, Byoungyoung LeeUSENIX Security 2026
