SymGX: Detecting Cross-boundary Pointer Vulnerabilities of SGX Applications via Static Symbolic Execution
Yuanpeng Wang, Ziqi Zhang, Ningyu He, Zhineng Zhong, Shengjian Guo, Qinkun Bao, Ding Li, Yao Guo, Xiangqun Chen
摘要
Intel Security Guard Extensions (SGX) have shown effectiveness in critical data protection. Recent symbolic execution-based techniques reveal that SGX applications are susceptible to memory corruption vulnerabilities. While existing approaches focus on conventional memory corruption in ECalls of SGX applications, they overlook an important type of SGX dedicated vulnerability: cross-boundary pointer vulnerabilities. This vulnerability is critical for SGX applications since they heavily utilize pointers to exchange data between secure enclaves and untrusted environments. Unfortunately, none of the existing symbolic execution approaches can effectively detect cross-boundary pointer vulnerabilities due to the lack of an SGX-specific analysis model that properly handles three unique features of SGX applications: Multi-entry Arbitrary-order Execution, Stateful Execution, and Context-aware Pointers. To address such problems, we propose a new analysis model named Global State Transition Graph with Context Aware Pointers (GSTG-CAP) that simulates properties-preserving execution behaviors for SGX applications and drives symbolic execution for vulnerability detection. Based on GSTG-CAP, we build a novel symbolic execution-based vulnerability detector named SYMGX to detect cross-boundary pointer vulnerabilities. According to our evaluation, SYMGX can find 30 0-DAY vulnerabilities in 14 open-source projects, three of which have been confirmed by developers. SYMGX also outperforms two state-of-the-art tools, COIN and TeeRex, in terms of effectiveness, efficiency, and accuracy.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Pandora: Principled Symbolic Validation of Intel SGX Enclave RuntimesFritz Alder, Lesly-Ann Daniel, David F. Oswald, Frank Piessens 等S&P 2024 · 被引用 12 次
- Recurring Vulnerability Detection: How Far Are We?Yiheng Cao, Susheng Wu, Ruisi Wang, Bihuan Chen 等ISSTA 2025 · 被引用 1 次
- Characterizing Trust Boundary Vulnerabilities in TEE Container Systems: An Empirical StudyWeijie Liu, Hongbo Chen, Shuo Huai, Zhen Xu 等FSE 2026
- The Cost of Performance: Breaking ThreadX with Kernel Object Masquerading AttacksXinhui Shao, Zhen Ling, Yue Zhang, Huaiyu Yan 等USENIX Security 2025
- KingsGuard: Enclave Data Protection Under Real-World TEE VulnerabilitiesSaltanat Firdous Allaqband, Deepanjali S, Rohit Srinivas R G, Devashish Gosain 等CCS 2026
它引用的顶会 Paper22
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck 等S&P 2020 · 被引用 369 次
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 被引用 329 次
- Panoply: Low-TCB Linux Applications With SGX EnclavesShweta Shinde, Dat Le Tien, Shruti Tople, Prateek SaxenaNDSS 2017 · 被引用 274 次
- SGX-Shield: Enabling Address Space Layout Randomization for SGX ProgramsJaebaek Seo, Byoungyoung Lee, Seong-Min Kim, Ming-Wei Shih 等NDSS 2017 · 被引用 227 次
相关 Paper
- TeeRex: Discovery and Exploitation of Memory Corruption Vulnerabilities in SGX EnclavesTobias Cloosters, Michael Rodler, Lucas DaviUSENIX Security 2020
- SGXFuzz: Efficiently Synthesizing Nested Structures for SGX Enclave FuzzingTobias Cloosters, Johannes Willbold, Thorsten Holz, Lucas DaviUSENIX Security 2022
- EnclaveFuzz: Finding Vulnerabilities in SGX ApplicationsLiheng Chen, Zheming Li, Zheyu Ma, Yuan Li 等NDSS 2024
- The Guard's Dilemma: Efficient Code-Reuse Attacks Against Intel SGXAndrea Biondo, Mauro Conti, Lucas Davi, Tommaso Frassetto 等USENIX Security 2018 · 被引用 126 次
- Hacking in Darkness: Return-oriented Programming against Secure EnclavesJae-Hyuk Lee, Jin Soo Jang, Yeongjin Jang, Nohyun Kwak 等USENIX Security 2017 · 被引用 191 次
