Midas: Systematic Kernel TOCTTOU Protection
Atri Bhattacharyya, Uros Tesic, Mathias Payer
摘要
Double-fetch bugs are a plague across all major operating system kernels. They occur when data is fetched twice across the user/kernel trust boundary while allowing concurrent modification. Such bugs enable an attacker to illegally access memory, cause denial of service, or to escalate privileges. So far, the only protection against double-fetch bugs is to detect and fix them. However, they remain incredibly hard to find. Similarly, they fundamentally prohibit efficient, kernel-based stateful system call filtering. Thus, we propose Midas to mitigate double-fetch bugs. Midas creates on-demand snapshots and copies of accessed data, enforcing our key invariant that throughout a system call's lifetime, every read to a userspace object will return the same value. Midas shows no noticeable drop in performance when evaluated on compute-bound workloads. On system call heavy workloads, Midas incurs 0.2-14% performance overhead, while protecting the kernel against any TOCTTOU attacks. On average, Midas shows a 3.4% overhead on diverse workloads across two benchmark suites.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- ADOC: Automatically Harmonizing Dataflow Between Components in Log-Structured Key-Value Stores for Improved PerformanceJinghuan Yu, Sam H. Noh, Young-ri Choi, Chun Jason XueFAST 2023 · 被引用 52 次
- SafeFetch: Practical Double-Fetch Protection with Kernel-Fetch CachingVictor Duta, Mitchel Aloserij, Cristiano GiuffridaUSENIX Security 2024 · 被引用 2 次
- IsolatOS: Detecting Double Fetch Bugs in COTS RTOS by Re-enabling Kernel IsolationYingjie Cao, Xiaogang Zhu, Dean Sullivan, Haowei Yang 等NDSS 2026 · 被引用 1 次
- EnclaveFuzz: Finding Vulnerabilities in SGX ApplicationsLiheng Chen, Zheming Li, Zheyu Ma, Yuan Li 等NDSS 2024
- Blindfold: Confidential Memory Management by Untrusted Operating SystemCaihua Li, Seung-Seob Lee, Lin ZhongNDSS 2025
它引用的顶会 Paper4
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Precise and Scalable Detection of Double-Fetch Bugs in OS KernelsMeng Xu, Chenxiong Qian, Kangjie Lu, Michael Backes 等S&P 2018 · 被引用 95 次
- How Double-Fetch Situations turn into Double-Fetch Vulnerabilities: A Study of Double Fetches in the Linux KernelPengfei Wang, Jens Krinke, Kai Lu, Gen Li 等USENIX Security 2017 · 被引用 66 次
- Rebooting Virtual Memory with MidgardSiddharth Gupta, Atri Bhattacharyya, Yunho Oh, Abhishek Bhattacharjee 等ISCA 2021 · 被引用 24 次
相关 Paper
- Check It Again: Detecting Lacking-Recheck Bugs in OS KernelsWenwen Wang, Kangjie Lu, Pen-Chung YewCCS 2018 · 被引用 49 次
- WarpAttack: Bypassing CFI through Compiler-Introduced Double-FetchesJianhao Xu, Luca Di Bartolomeo, Flavio Toffalini, Bing Mao 等S&P 2023
- Static Detection of TOCTOU Bugs Caused by Kernel RacesGui-Dong Han, Jia-Ju Bai, Qiu-Ji Chen, Jiqiang LuUSENIX Security 2026
- Using Trātṛ to tame Adversarial SynchronizationYuvraj Patel, Chenhao Ye, Akshat Sinha, Abigail Matthews 等USENIX Security 2022
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris 等NDSS 2016 · 被引用 141 次
