Detecting Kernel Memory Bugs through Inconsistent Memory Management Intention Inferences
Dinghao Liu, Zhipeng Lu, Shouling Ji, Kangjie Lu, Jianhai Chen, Zhenguang Liu, Dexin Liu, Renyi Cai, Qinming He
摘要
Modern operating system kernels, typically written in lowlevel languages such as C and C++, are tasked with managing extensive memory resources. Memory-related errors, such as memory leak and memory corruption, are common occurrences and constantly introduced. Traditional detection methods often rely on taint analysis, which suffer from scalability issues (i.e., path explosion) when applied to complex OS kernels. Recent research has pivoted towards leveraging techniques like function pairing or similarity analysis to overcome this challenge. These approaches identify memory errors by referencing code that is either frequently used or semantically similar. However, these techniques have limitations when applied to customized code, which may lack a sufficient corpus of code snippets to facilitate effective function pairing or similarity analysis. This deficiency hinders their applicability in kernel analysis where unique or proprietary code is prevalent. In this paper, we propose a novel methodology for detecting memory bugs based on inconsistent memory management intentions (IMMI). Our insight is that many memory bugs, despite their varied manifestations, stem from a common underlying issue: the ambiguity in ownership and lifecycle management of memory objects, especially when these objects are passed across various functions. Memory bugs emerge when the memory management strategies of the caller and callee functions misalign for a given memory object. IMMI aims to model and clarify these inconsistent intentions, thereby mitigating the prevalence of such bugs. Our methodology offers two primary advantages over existing techniques: (1) It utilizes a fine-grained memory management model that obviates the need for extensive data-flow tracking, and (2) it does not rely on similarity analysis or the identification of function pairs, making it highly effective in the context of customized code. To enhance the capabilities of IMMI, we have integrated a large language model (LLM) to assist in the interpretation of implicit kernel resource management mechanisms. We have Shouling Ji and Qinming He are the co-corresponding authors. implemented IMMI and evaluated it against the Linux kernel. IMMI effectively found 80 new memory bugs (including 23 memory corruptions and 57 memory leaks) with 35% false discovery rate. Most of them are missed by the state-of-the-art memory bug detection tools.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- One Bug, Hundreds Behind: LLMs for Large-Scale Bug DiscoveryQiushi Wu, Yue Xiao, Dhilung Kirat, Kevin Eykholt 等ICML 2026 · 被引用 5 次
- SYSYPHUZZ: the Pressure of More CoverageZezhong Ren, Han Zheng, Zhiyao Feng, Qinying Wang 等NDSS 2026 · 被引用 1 次
- Death by a Thousand Drips: Uncovering Critical Resource Leaks in the Windows EcosystemFeng Dong, Jianting Gao, Yunpeng Tian, Weifeng Yuan 等USENIX Security 2026
- Feature Slice Matching for Precise Bug DetectionKe Ma, Jianjun Huang, Wei You, Bin Liang 等FSE 2026
- The Digital Cybersecurity Expert: How Far Have We Come?Dawei Wang, Geng Zhou, Xianglong Li, Yu Bai 等S&P 2025
它引用的顶会 Paper20
- Where Does It Go?: Refining Indirect-Call Targets with Multi-Layer Type AnalysisKangjie Lu, Hong HuCCS 2019 · 被引用 142 次
- GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program AnalysisYuqiang Sun, Daoyuan Wu, Yue Xue, Han Liu 等ICSE 2024 · 被引用 131 次
- FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free VulnerabilitiesWei Wu, Yueqi Chen, Jun Xu, Xinyu Xing 等USENIX Security 2018 · 被引用 124 次
- APISan: Sanitizing API Usages through Semantic Cross-CheckingInsu Yun, Changwoo Min, Xujie Si, Yeongjin Jang 等USENIX Security 2016 · 被引用 107 次
- Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints InferencesKangjie Lu, Aditya Pakki, Qiushi WuUSENIX Security 2019 · 被引用 97 次
相关 Paper
- MLEE: Effective Detection of Memory Leaks on Early-Exit Paths in OS KernelsWenwen WangUSENIX ATC 2021 · 被引用 15 次
- Goshawk: Hunting Memory Corruptions via Structure-Aware and Object-Centric Memory Operation SynopsisYunlong Lyu, Yi Fang, Yiwei Zhang, Qibin Sun 等S&P 2022 · 被引用 26 次
- K-Miner: Uncovering Memory Corruption in LinuxDavid Gens, Simon Schmitt, Lucas Davi, Ahmad-Reza SadeghiNDSS 2018 · 被引用 58 次
- Non-Distinguishable Inconsistencies as a Deterministic Oracle for Detecting Security BugsQingyang Zhou, Qiushi Wu, Dinghao Liu, Shouling Ji 等CCS 2022 · 被引用 2 次
- OZZ: Identifying Kernel Out-of-Order Concurrency Bugs with In-Vivo Memory Access ReorderingDae R. Jeong, Yewon Choi, Byoungyoung Lee, Insik Shin 等SOSP 2024 · 被引用 4 次
