SoK: On the Fragility of Memory Error Exploit Mitigations
Adriaan Jacobs, Mahmoud Ammar, Stijn Volckaert
摘要
The perennial war in memory has long been shaped by a continuous arms race: defenses are deployed, bypasses emerge, and stronger mitigations follow, only for the cycle to repeat. This pattern persists in part due to the fragility of many defenses, which often fail when assumptions change. Such fragility reflects how security guarantees are assessed, often through ad hoc reasoning tied to specific threat models. In a fast-evolving landscape of polyglot applications and heterogeneous systems, manually re-evaluating these guarantees for every new context is both labor-intensive and error-prone.
This SoK advocates for a more systematic, adversary-aware approach. We introduce a graph-based framework for evaluating the fragility of memory safety defenses by modeling the progression of memory corruption exploits, and where, how, and under what assumptions defenses intervene and may fail. We demonstrate the utility of this model by revisiting flaws in prominent defenses and showing how their shortcomings could have been anticipated. Finally, we release open-source tooling that implements our model and supports systematized and semi-automated fragility testing.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper72
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua 等S&P 2016 · 被引用 420 次
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler 等USENIX Security 2019 · 被引用 247 次
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na 等S&P 2019 · 被引用 196 次
- SoK: Shining Light on Shadow StacksNathan Burow, Xinping Zhang, Mathias PayerS&P 2019 · 被引用 170 次
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez 等USENIX Security 2019 · 被引用 168 次
相关 Paper
- HeapHopper: Bringing Bounded Model Checking to Heap Implementation SecurityMoritz Eckert, Antonio Bianchi, Ruoyu Wang, Yan Shoshitaishvili 等USENIX Security 2018 · 被引用 62 次
- SafetyMem: Adaptive Jailbreak Defense via Dual-Component Safety MemoryHao Wang, Ziyi Ni, Huacan Wang, Pin Lyu 等ACL 2026
- From Prompt to Pwn: Exploiting GPU Memory Errors During ML InferenceJonas Roels, Adriaan Jacobs, Silviu Vlasceanu, Mahmoud Ammar 等CCS 2026
- K-Miner: Uncovering Memory Corruption in LinuxDavid Gens, Simon Schmitt, Lucas Davi, Ahmad-Reza SadeghiNDSS 2018 · 被引用 58 次
- SoK: Take a Deep Step into Linux Kernel Hardening Effectiveness from the Offensive-Defensive PerspectiveYinhao Hu, Pengyu Ding, Zhenpeng Lin, Dongliang Mu 等NDSS 2026 · 被引用 3 次
