CRCount: Pointer Invalidation with Reference Counting to Mitigate Use-after-free in Legacy C/C++
Jangseop Shin, Donghyun Kwon, Jiwon Seo, Yeongpil Cho, Yunheung Paek
摘要
Pointer invalidation has been a popular approach adopted in many recent studies to mitigate use-after-free errors. The approach can be divided largely into two different schemes: explicit invalidation and implicit invalidation. The former aims to eradicate the root cause of use-after-free errors by explicitly invalidating every dangling pointer. In contrast, the latter aims to prevent dangling pointers by freeing an object only if there is no pointer referring to it. A downside of the explicit scheme is that it is expensive, as it demands high-cost algorithms or a large amount of space to maintain up-to-date lists of pointer locations linking to each object. Implicit invalidation is more efficient in that even without any explicit effort, it can eliminate dangling pointers by leaving objects undeleted until all the links between the objects and their referring pointers vanish by themselves during program execution. However, such an argument only holds if the scheme knows exactly when each link is created and deleted. Reference counting is a traditional method to determine the existence of reference links between objects and pointers. Unfortunately, impeccable reference counting for legacy C/C++ code is very difficult and expensive to achieve in practice, mainly because of the type unsafe operations in the code. In this paper, we present a solution, called CRCount, to the use-after-free problem in legacy C/C++. For effective and efficient problem solving, CRCount is armed with the pointer footprinting technique that enables us to compute, with high accuracy, the reference count of every object referred to by the pointers in the legacy code. Our experiments demonstrate that CRCount mitigates the useafter-free errors with a lower performance-wise and space-wise overhead than the existing pointer invalidation solutions.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper20
- Cornucopia: Temporal Safety for CHERI HeapsNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Sam Ainsworth 等S&P 2020 · 被引用 71 次
- PTAuth: Temporal Memory Safety via Robust Points-to AuthenticationReza Mirzazade Farkhani, Mansour Ahmadi, Long LuUSENIX Security 2021 · 被引用 67 次
- MarkUs: Drop-in use-after-free prevention for low-level languagesSam Ainsworth, Timothy M. JonesS&P 2020 · 被引用 63 次
- Preventing Use-After-Free Attacks with Fast Forward AllocationBrian Wickman, Hong Hu, Insu Yun, Daehee Jang 等USENIX Security 2021 · 被引用 53 次
- Detecting Kernel Refcount Bugs with Two-Dimensional Consistency CheckingXin Tan, Yuan Zhang, Xiyu Yang, Kangjie Lu 等USENIX Security 2021 · 被引用 26 次
它引用的顶会 Paper2
相关 Paper
- FreeWill: Automatically Diagnosing Use-after-free Bugs via Reference Miscounting Detection on BinariesLiang He, Hong Hu, Purui Su, Yan Cai 等USENIX Security 2022
- A Robust and Efficient Defense against Use-after-Free Exploits via Concurrent Pointer SweepingDaiping Liu, Mingwei Zhang, Haining WangCCS 2018 · 被引用 43 次
- CountDown: Refcount-guided Fuzzing for Exposing Temporal Memory Errors in Linux KernelShuangpeng Bai, Zhechang Zhang, Hong HuCCS 2024 · 被引用 4 次
- MineSweeper: a "clean sweep" for drop-in use-after-free preventionMárton Erdos, Sam Ainsworth, Timothy M. JonesASPLOS 2022 · 被引用 13 次
- Concurrent deferred reference counting with constant-time overheadDaniel Anderson, Guy E. Blelloch, Yuanhao WeiPLDI 2021 · 被引用 26 次
