Control Flow and Pointer Integrity Enforcement in a Secure Tagged Architecture
Ravi Theja Gollapudi, Gokturk Yuksek, David Demicco, Matthew Cole, Gaurav Kothari, Rohit Kulkarni, Xin Zhang, Kanad Ghose, Aravind Prakash, Zerksis Umrigar
摘要
Control flow attacks exploit software vulnerabilities to divert the flow of control into unintended paths to ultimately execute attack code. This paper explores the use of instruction and data tagging as a general means of thwarting such control flow attacks, including attacks that rely on violating pointer integrity. Using specific types of narrow-width data tags along with narrow-width instruction tags embedded within the binary facilitates the security policies required to protect against such attacks, leading to a practically viable solution. Co-locating instruction tags close to their corresponding instructions within cache lines eliminates the need for separate mechanisms for instruction tag accesses. Information gleaned from the analysis phase of a compiler is augmented and used to generate the instruction and data tags. A full-stack implementation that consists of a modified LLVM compiler, modified Linux OS support for tags and a FPGA-implemented CPU hardware prototype for enforcing CFI, data pointer and code pointer integrity is demonstrated. With a modest hardware enhancement, the execution time of benchmark applications on the prototype system is shown to be limited to low, single-digit percentages of a baseline system without tagging.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- DMAAUTH: A Lightweight Pointer Integrity-based Secure Architecture to Defeat DMA AttacksXingkai Wang, Wenbo Shen, Yujie Bu, Jinmeng Zhou 等USENIX Security 2024 · 被引用 2 次
- CCTAG: Configurable and Combinable Tagged ArchitectureZhanpeng Liu, Yi Rong, Chenyang Li, Wende Tan 等NDSS 2025
- Lippen: a Lightweight in-Place Pointer Encryption Architecture for Pointer IntegrityErfan Iravani, Lalit Prasad Peri, Mohannad Ismail, Charitha Tumkur Siddalingaradhya 等ISCA 2026
它引用的顶会 Paper9
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua 等S&P 2016 · 被引用 420 次
- HDFI: Hardware-Assisted Data-Flow IsolationChengyu Song, Hyungon Moon, Monjur Alam, Insu Yun 等S&P 2016 · 被引用 146 次
- Enforcing Unique Code Target Property for Control-Flow IntegrityHong Hu, Chenxiong Qian, Carter Yagemann, Simon Pak Ho Chung 等CCS 2018 · 被引用 142 次
- Efficient Protection of Path-Sensitive Control SecurityRen Ding, Chenxiong Qian, Chengyu Song, William Harris 等USENIX Security 2017 · 被引用 123 次
- TIMBER-V: Tag-Isolated Memory Bringing Fine-grained Enclaves to RISC-VSamuel Weiser, Mario Werner, Ferdinand Brasser, Maja Malenko 等NDSS 2019 · 被引用 115 次
相关 Paper
- COGENT: Adaptable Compiler Toolchain for Tagging RISC-V BinariesDavid B. Demicco, Matthew Cole, Gokturk Yuksek, Ravi Theja Gollapudi 等ASPLOS 2025
- SpecCFI: Mitigating Spectre Attacks using CFI Informed SpeculationEsmaeil Mohammadian Koruyeh, Shirin Haji Amin Shirazi, Khaled N. Khasawneh, Chengyu Song 等S&P 2020 · 被引用 74 次
- VTrust: Regaining Trust on Virtual CallsChao Zhang, Dawn Song, Scott A. Carr, Mathias Payer 等NDSS 2016 · 被引用 91 次
- Camouflage: Hardware-assisted CFI for the ARM Linux kernelRémi Denis-Courmont, Hans Liljestrand, Carlos Chinea Perez, Jan-Erik EkbergDAC 2020 · 被引用 18 次
- Protecting the Stack with Metadata Policies and Tagged HardwareNick Roessler, André DeHonS&P 2018 · 被引用 37 次
