TAILCHECK: A Lightweight Heap Overflow Detection Mechanism with Page Protection and Tagged Pointers
Amogha Udupa Shankaranarayana Gopal, Raveendra Soori, Michael Ferdman, Dongyoon Lee
摘要
A heap overflow vulnerability occurs when a program written in an unmanaged language such as C or C ++ accesses a memory location beyond an object allocation boundary. Malicious users may exploit this vulnerability to corrupt an adjacent object in memory, creating an entry point for a security attack. Despite decades of research, unfortunately, it still remains challenging to detect heap overflow vulnerabilities in realworld programs at a low cost.
We present TAILCHECK, a new lightweight heap overflow detection scheme that leverages page protection and pointer tagging. When an object is created, TAILCHECK allocates an additional page-protected shadow object, called a TailObject, placing the distance from the object to its TailObject as a tag stored in the unused high-order bits of the object pointer. For every access to the original object, TAILCHECK performs an additional memory access to the TailObject, whose address is computed using the tag. Heap overflows are detected as page faults when an access occurs beyond the TailObject. We evaluated TAILCHECK with four server applications (apache, nginx, memcached, redis) and the SPEC CPU2017 and SPEC CPU2006 benchmarks, successfully finding heap overflows in SPEC CPU2017 gcc. TAILCHECK experiences 4% and 3% run-time overhead for the average and tail (99%) latencies for server applications; and only 33% and 29% runtime overhead for SPEC CPU2017 and SPEC CPU2006, respectively, less than the state-of-the-art solution.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Sticky Tags: Efficient and Deterministic Spatial Memory Error Mitigation using Persistent Memory TagsFloris Gorter, Taddeus Kroes, Herbert Bos, Cristiano GiuffridaS&P 2024 · 被引用 22 次
- ShadowBound: Efficient Heap Memory Protection Through Advanced Metadata Management and Customized Compiler OptimizationZheng Yu, Ganxiang Yang, Xinyu XingUSENIX Security 2024 · 被引用 13 次
- GIANTSAN: Efficient Memory Sanitization with Segment FoldingHao Ling, Heqing Huang, Chengpeng Wang, Yuandao Cai 等ASPLOS 2024 · 被引用 8 次
- Highly Automated Verification of Security Properties for Unmodified System SoftwareGanxiang Yang, Wei Qiang, Yi Rong, Xuheng Li 等ASPLOS 2026 · 被引用 1 次
- QuickSafe: Targeted Hardening Against Memory CorruptionJohannes Blaser, Floris Gorter, Klaus von Gleissenthall, Herbert BosS&P 2026
它引用的顶会 Paper10
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na 等S&P 2019 · 被引用 196 次
- UniSan: Proactive Kernel Memory Initialization to Eliminate Data LeakagesKangjie Lu, Chengyu Song, Taesoo Kim, Wenke LeeCCS 2016 · 被引用 81 次
- Oscar: A Practical Page-Permissions-Based Scheme for Thwarting Dangling PointersThurston H. Y. Dang, Petros Maniatis, David A. WagnerUSENIX Security 2017 · 被引用 77 次
- Safelnit: Comprehensive and Practical Mitigation of Uninitialized Read VulnerabilitiesAlyssa Milburn, Herbert Bos, Cristiano GiuffridaNDSS 2017 · 被引用 42 次
- PACMem: Enforcing Spatial and Temporal Memory Safety via ARM Pointer AuthenticationYuan Li, Wende Tan, Zhizheng Lv, Songtao Yang 等CCS 2022 · 被引用 30 次
相关 Paper
- CAMP: Compiler and Allocator-based Heap Memory ProtectionZhenpeng Lin, Zheng Yu, Ziyi Guo, Simone Campanoni 等USENIX Security 2024 · 被引用 14 次
- Towards Efficient Heap Overflow DiscoveryXiangkun Jia, Chao Zhang, Purui Su, Yi Yang 等USENIX Security 2017 · 被引用 36 次
- Hardware-based Always-On Heap Memory SafetyYonghae Kim, Jaekyu Lee, Hyesoon KimMICRO 2020 · 被引用 41 次
- Prober: Practically Defending Overflows with Page ProtectionHongyu Liu, Ruiqin Tian, Tongping Liu, Bin RenASE 2020 · 被引用 3 次
- Look Before You Access: Efficient Heap Memory Safety for Embedded Systems on ARMv8-MJeonghwan Kang, Jaeyeol Park, Jiwon Seo, Donghyun KwonDAC 2024 · 被引用 1 次
