Top of the Heap: Efficient Memory Error Protection of Safe Heap Objects
Kaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson, Gang Tan, Trent Jaeger
摘要
Heap memory errors remain a major source of software vulnerabilities. Existing memory safety defenses aim at protecting all objects, resulting in high performance cost and incomplete protection. Instead, we propose an approach that accurately identifies objects that are inexpensive to protect, and design a method to protect such objects comprehensively from all classes of memory errors. Towards this goal, we introduce the Uriah system that (1) statically identifies the heap objects whose accesses satisfy spatial and type safety, and (2) dynamically allocates such "safe" heap objects on an isolated safe heap to enforce a form of temporal safety while preserving spatial and type safety, called temporal allocated-type safety. Uriah finds 72.0% of heap allocation sites produce objects whose accesses always satisfy spatial and type safety in the SPEC CPU2006/2017 benchmarks, 5 server programs, and Firefox, which are then isolated on a safe heap using Uriah allocator to enforce temporal allocated-type safety. Uriah incurs only 2.9% and 2.6% runtime overhead, along with 9.3% and 5.4% memory overhead, on the SPEC CPU 2006 and 2017 benchmarks, while preventing exploits on all the heap memory errors in DARPA CGC binaries and 28 recent CVEs. Additionally, using existing defenses to enforce their memory safety guarantees on the unsafe heap objects significantly reduces overhead, enabling the protection of heap objects from all classes of memory errors at more practical costs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- QuickSafe: Targeted Hardening Against Memory CorruptionJohannes Blaser, Floris Gorter, Klaus von Gleissenthall, Herbert BosS&P 2026
- SoK: Challenges and Paths Toward Memory Safety for eBPFKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson 等S&P 2025
- SoK: On the Fragility of Memory Error Exploit MitigationsAdriaan Jacobs, Mahmoud Ammar, Stijn VolckaertUSENIX Security 2026
- Melting the Flesh of PHP's Memory HardeningYifan Wu, Xiaochuan Yu, Zhiyun QianUSENIX Security 2026
- Fast Pointer Nullification for Use-After-Free PreventionYubo Du, Youtao Zhang, Jun YangNDSS 2026
它引用的顶会 Paper33
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua 等S&P 2016 · 被引用 420 次
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez 等USENIX Security 2019 · 被引用 168 次
- Block Oriented Programming: Automating Data-Only AttacksKyriakos K. Ispoglou, Bader AlBassam, Trent Jaeger, Mathias PayerCCS 2018 · 被引用 143 次
- FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free VulnerabilitiesWei Wu, Yueqi Chen, Jun Xu, Xinyu Xing 等USENIX Security 2018 · 被引用 124 次
- Stack Bounds Protection with Low Fat PointersGregory J. Duck, Roland H. C. Yap, Lorenzo CavallaroNDSS 2017 · 被引用 121 次
相关 Paper
- The Taming of the Stack: Isolating Stack Data from Memory ErrorsKaiming Huang, Yongzhe Huang, Mathias Payer, Zhiyun Qian 等NDSS 2022
- ViK: practical mitigation of temporal memory safety violations through object ID inspectionHaehyun Cho, Jinbum Park, Adam Oest, Tiffany Bao 等ASPLOS 2022 · 被引用 13 次
- FreeGuard: A Faster Secure Heap AllocatorSam Silvestro, Hongyu Liu, Corey Crosser, Zhiqiang Lin 等CCS 2017 · 被引用 71 次
- Cornucopia: Temporal Safety for CHERI HeapsNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Sam Ainsworth 等S&P 2020 · 被引用 71 次
- PTAuth: Temporal Memory Safety via Robust Points-to AuthenticationReza Mirzazade Farkhani, Mansour Ahmadi, Long LuUSENIX Security 2021 · 被引用 67 次
