PT-Rand: Practical Mitigation of Data-only Attacks against Page Tables
Lucas Davi, David Gens, Christopher Liebchen, Ahmad-Reza Sadeghi
摘要
Kernel exploits constitute a powerful attack class allowing attackers to gain full control over a system. Various kernel hardening solutions have been proposed or deployed in practice to protect the kernel against code injection (e.g., DEP) or code-reuse exploits (e.g., CFI). However, the security of all these hardening techniques relies heavily on the assumption that kernel page tables cannot be manipulated, e.g., by means of dataonly attacks. Ensuring kernel page tables integrity is not only essential for kernel security but also a challenging task in practice since existing solutions require hardware trust anchors, costly hypervisors, or inefficient integrity checks. In this paper, we first motivate the importance of protecting kernel page tables by presenting a data-only attack against page tables to bypass the recently released CFI-based (Linux) kernel hardening technique RAP. Thereafter, we present the design and implementation of PT-Rand, the first practical solution to protect kernel page tables that does not suffer from the mentioned deficiencies of previous proposals. PT-Rand randomizes the location of page tables and tackles a number of challenges to ensure that the location of page tables is not leaked. This effectively prevents the attacker from manipulating access permissions of code pages, thereby enabling secure enforcement of kernel exploit mitigation technologies such as CFI. We extensively evaluate our prototype implementation of PT-Rand for the current Linux kernel on the popular Linux distribution Debian and report a low overhead of 0.22% for common benchmarks. Moreover, we combine RAP with PT-Rand to protect RAP against data-only attacks on kernel page tables. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- xMP: Selective Memory Protection for Kernel and User SpaceSergej Proskurin, Marius Momeu, Seyedhamed Ghavamnia, Vasileios P. Kemerlis 等S&P 2020 · 被引用 89 次
- IMIX: In-Process Memory Isolation EXtensionTommaso Frassetto, Patrick Jauernig, Christopher Liebchen, Ahmad-Reza SadeghiUSENIX Security 2018 · 被引用 77 次
- KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel VulnerabilitiesWei Wu, Yueqi Chen, Xinyu Xing, Wei ZouUSENIX Security 2019 · 被引用 75 次
- Harmonizing Performance and Isolation in Microkernels with Efficient Intra-kernel Isolation and CommunicationJinyu Gu, Xinyue Wu, Wentai Li, Nian Liu 等USENIX ATC 2020 · 被引用 51 次
- DynPTA: Combining Static and Dynamic Analysis for Practical Selective Data ProtectionTapti Palit, Jarin Firose Moon, Fabian Monrose, Michalis PolychronakisS&P 2021 · 被引用 48 次
它引用的顶会 Paper3
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua 等S&P 2016 · 被引用 420 次
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris 等NDSS 2016 · 被引用 141 次
- SKEE: A lightweight Secure Kernel-level Execution Environment for ARMAhmed M. Azab, Kirk Swidowski, Rohan Bhutkar, Jia Ma 等NDSS 2016 · 被引用 105 次
相关 Paper
- Breaking Kernel Address Space Layout Randomization with Intel TSXYeongjin Jang, Sangho Lee, Taesoo KimCCS 2016 · 被引用 174 次
- Leakage-Resilient Layout Randomization for Mobile DevicesKjell Braden, Lucas Davi, Christopher Liebchen, Ahmad-Reza Sadeghi 等NDSS 2016 · 被引用 90 次
- PTStore: Lightweight Architectural Support for Page Table IsolationWende Tan, Yangyu Chen, Yuan Li, Ying Liu 等DAC 2023 · 被引用 3 次
- HEAP LOCALIZATION: Cache Side-Channel Based Linux Kernel Heap Exploit TechniquesYoochan Lee, Sihyun Roh, Hyuk Kwon, Byoungyoung Lee 等S&P 2026
- Camouflage: Hardware-assisted CFI for the ARM Linux kernelRémi Denis-Courmont, Hans Liljestrand, Carlos Chinea Perez, Jan-Erik EkbergDAC 2020 · 被引用 18 次
