Playing for K(H)eaps: Understanding and Improving Linux Kernel Exploit Reliability
Kyle Zeng, Yueqi Chen, Haehyun Cho, Xinyu Xing, Adam Doupé, Yan Shoshitaishvili, Tiffany Bao
摘要
The dynamic of the Linux kernel heap layout significantly impacts the reliability of kernel heap exploits, making exploitability assessment challenging. Though techniques have been proposed to stabilize exploits in the past, little scientific research has been conducted to evaluate their effectiveness and explore their working conditions. In this paper, we present a systematic study of the kernel heap exploit reliability problem. We first interview kernel security experts, gathering commonly adopted exploitation stabilization techniques and expert opinions about these techniques. We then evaluate these stabilization techniques on 17 real-world kernel heap exploits. The results indicate that many kernel security experts have incorrect opinions on exploitation stabilization techniques. To help the security community better understand exploitation stabilization, we inspect our experiment results and design a generic kernel heap exploit model. We use the proposed exploit model to interpret the exploitation unreliability issue and analyze why stabilization techniques succeed or fail. We also leverage the model to propose a new exploitation technique. Our experiment indicates that the new stabilization technique improves Linux kernel exploit reliability by 14.87% on average. Combining this newly proposed technique with existing stabilization approaches produces a composite stabilization method that achieves a 135.53% exploitation reliability improvement on average, outperforming exploit stabilization by professional security researchers by 67.86%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper26
- DirtyCred: Escalating Privilege in Linux KernelZhenpeng Lin, Yuhang Wu, Xinyu XingCCS 2022 · 被引用 30 次
- SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux KernelLukas Maar, Stefan Gast, Martin Unterguggenberger, Mathias Oberhuber 等USENIX Security 2024 · 被引用 16 次
- Go Go Gadget Hammer: Flipping Nested Pointers for Arbitrary Data LeakageYoussef Tobah, Andrew Kwong, Ingab Kang, Daniel Genkin 等USENIX Security 2024 · 被引用 11 次
- RetSpill: Igniting User-Controlled Data to Burn Away Linux Kernel ProtectionsKyle Zeng, Zhenpeng Lin, Kangjie Lu, Xinyu Xing 等CCS 2023 · 被引用 9 次
- SCAVY: Automated Discovery of Memory Corruption Targets in Linux Kernel for Privilege EscalationErin Avllazagaj, Yonghwi Kwon, Tudor DumitrasUSENIX Security 2024 · 被引用 7 次
它引用的顶会 Paper17
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher 等NDSS 2016 · 被引用 1,021 次
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp 等CCS 2016 · 被引用 278 次
- Breaking Kernel Address Space Layout Randomization with Intel TSXYeongjin Jang, Sangho Lee, Taesoo KimCCS 2016 · 被引用 174 次
相关 Paper
- HEAP LOCALIZATION: Cache Side-Channel Based Linux Kernel Heap Exploit TechniquesYoochan Lee, Sihyun Roh, Hyuk Kwon, Byoungyoung Lee 等S&P 2026
- SLAKE: Facilitating Slab Manipulation for Exploiting Vulnerabilities in the Linux KernelYueqi Chen, Xinyu XingCCS 2019 · 被引用 76 次
- SeaK: Rethinking the Design of a Secure Allocator for OS KernelZicheng Wang, Yicheng Guang, Yueqi Chen, Zhenpeng Lin 等USENIX Security 2024 · 被引用 1 次
- Take a Step Further: Understanding Page Spray in Linux Kernel ExploitationZiyi Guo, Dang K. Le, Zhenpeng Lin, Kyle Zeng 等USENIX Security 2024 · 被引用 6 次
- Towards Automatic and Precise Heap Layout Manipulation for General-Purpose ProgramsRunhao Li, Bin Zhang, Jiongyi Chen, Wenfeng Lin 等NDSS 2023
