NoJITsu: Locking Down JavaScript Engines
Taemin Park, Karel Dhondt, David Gens, Yeoul Na, Stijn Volckaert, Michael Franz
摘要
Data-only attacks against dynamic scripting environments have become common. Web browsers and other modern applications embed scripting engines to support interactive content. The scripting engines optimize performance via just-in-time compilation. Since applications are increasingly hardened against code-reuse attacks, adversaries are looking to achieve code execution or elevate privileges by corrupting sensitive data like the intermediate representation of optimizing JIT compilers. This has inspired numerous defenses for just-in-time compilers.
Our paper demonstrates that securing JIT compilation is not sufficient. First, we present a proof-of-concept data-only attack against a recent version of Mozilla’s SpiderMonkey JIT in which the attacker only corrupts heap objects to successfully issue a system call from within bytecode execution at run time. Previous work assumed that bytecode execution is safe by construction since interpreters only allow a narrow set of benign instructions and bytecode is always checked for validity before execution. We show that this does not prevent malicious code execution in practice. Second, we design a novel defense, dubbed NoJITsu to protect complex, real-world scripting engines from data-only attacks against interpreted code. The key idea behind our defense is to allow fine-grained memory access control by analyzing, identifying, isolating, and protecting individual memory regions focusing on their role in code generation at any point in the JavaScript engine. For this we combine automated analysis and instrumentation, compartmentalization, and Intel’s Memory-Protection Keys to secure SpiderMonkey against previous and our new attack. We implement and thoroughly test our implementation using a number of real-world scenarios as well as standard benchmarks. We show that NoJITsu successfully thwarts code-reuse as well as data-only attacks against any part of the scripting engine while offering a modest run-time overhead of only 5%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- You shall not (by)pass!: practical, secure, and fast PKU-based sandboxingAlexios Voulimeneas, Jonas Vinck, Ruben Mechelinck, Stijn VolckaertEuroSys 2022 · 被引用 33 次
- Towards a verified range analysis for JavaScript JITsFraser Brown, John Renner, Andres Nötzli, Sorin Lerner 等PLDI 2020 · 被引用 28 次
- Icarus: Trustworthy Just-In-Time Compilers with Symbolic Meta-ExecutionNaomi Smith, Abhishek Sharma, John Renner, David Thien 等SOSP 2024 · 被引用 17 次
- Isolating functions at the hardware limit with virtinesNicholas C. Wanninger, Joshua J. Bowden, Kirtankumar Shetty, Ayush Garg 等EuroSys 2022 · 被引用 17 次
- CETIS: Retrofitting Intel CET for Generic and Efficient Intra-process Memory IsolationMengyao Xie, Chenggang Wu, Yinqian Zhang, Jiali Xu 等CCS 2022 · 被引用 14 次
它引用的顶会 Paper11
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Shreds: Fine-Grained Execution Units with Private MemoryYaohui Chen, Sebassujeen Reymondjohnson, Zhichuang Sun, Long LuS&P 2016 · 被引用 116 次
- VTrust: Regaining Trust on Virtual CallsChao Zhang, Dawn Song, Scott A. Carr, Mathias Payer 等NDSS 2016 · 被引用 91 次
- Leakage-Resilient Layout Randomization for Mobile DevicesKjell Braden, Lucas Davi, Christopher Liebchen, Ahmad-Reza Sadeghi 等NDSS 2016 · 被引用 90 次
相关 Paper
- JITGuard: Hardening Just-in-time Compilers with SGXTommaso Frassetto, David Gens, Christopher Liebchen, Ahmad-Reza SadeghiCCS 2017 · 被引用 37 次
- A Call to ARMs: Understanding the Costs and Benefits of JIT Spraying MitigationsWilson Lian, Hovav Shacham, Stefan SavageNDSS 2017 · 被引用 7 次
- What Cannot Be Read, Cannot Be Leveraged? Revisiting Assumptions of JIT-ROP DefensesGiorgi Maisuradze, Michael Backes, Christian RossowUSENIX Security 2016 · 被引用 41 次
- JIT-Picking: Differential Fuzzing of JavaScript EnginesLukas Bernhard, Tobias Scharnowski, Moritz Schloegel, Tim Blazytko 等CCS 2022 · 被引用 42 次
- FUZZILLI: Fuzzing for JavaScript JIT Compiler VulnerabilitiesSamuel Groß, Simon Koch, Lukas Bernhard, Thorsten Holz 等NDSS 2023
