MineSweeper: a "clean sweep" for drop-in use-after-free prevention
Márton Erdos, Sam Ainsworth, Timothy M. Jones
摘要
Low-level languages, which require manual memory management from the programmer, remain in wide use for performance-critical applications. Memory-safety bugs are common, and now a major source of exploits. In particular, a use-after-free bug occurs when an object is erroneously deallocated, whilst pointers to it remain active in memory, and those (dangling) pointers are later used to access the object. An attacker can reallocate the memory area backing an erroneously freed object, then overwrite its contents, injecting carefully chosen data into the host program, thus altering its execution and achieving privilege escalation.
We present MineSweeper, a system to mitigate use-after-free vulnerabilities by retaining freed allocations in a quarantine, until no pointers to them remain in program memory, thus preventing their reallocation until it is safe. MineSweeper performs efficient linear sweeps of memory to identify quarantined items that have no dangling pointers to them, and thus can be safely reallocated. This allows MineSweeper to be significantly more efficient than previous transitive marking procedure techniques.
MineSweeper, attached to JeMalloc, improves security at an acceptable overhead in memory footprint (11.1% on average) and an execution-time cost of only 5.4% (geometric mean for SPEC CPU2006), with 9.6% additional threaded CPU usage. These figures considerably improve on the state-of-the-art for non-probabilistic drop-in temporal-safety systems, and make MineSweeper the only such scheme suitable for deployment in real-world production environments.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Sticky Tags: Efficient and Deterministic Spatial Memory Error Mitigation using Persistent Memory TagsFloris Gorter, Taddeus Kroes, Herbert Bos, Cristiano GiuffridaS&P 2024 · 被引用 22 次
- BUDAlloc: Defeating Use-After-Free Bugs by Decoupling Virtual Address Management from KernelJunho Ahn, Jaehyeon Lee, Kanghyuk Lee, Wooseok Gwak 等USENIX Security 2024 · 被引用 6 次
- PICASSO: Scaling CHERI Use-After-Free Protection to Millions of Allocations using Colored CapabilitiesMerve Gülmez, Ruben Sturm, Hossam ElAtali, Håkan Englund 等USENIX Security 2026 · 被引用 5 次
- StarMalloc: Verifying a Modern, Hardened Memory AllocatorAntonin Reitz, Aymeric Fromherz, Jonathan ProtzenkoOOPSLA 2024 · 被引用 5 次
- PoisonCap: Efficient Hierarchical Temporal Safety for CHERIYuecheng Wang, Jonathan Woodruff, Alfredo Mazzinghi, Peter Rugg 等CCS 2026 · 被引用 3 次
它引用的顶会 Paper8
- Oscar: A Practical Page-Permissions-Based Scheme for Thwarting Dangling PointersThurston H. Y. Dang, Petros Maniatis, David A. WagnerUSENIX Security 2017 · 被引用 77 次
- Cornucopia: Temporal Safety for CHERI HeapsNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Sam Ainsworth 等S&P 2020 · 被引用 71 次
- FreeGuard: A Faster Secure Heap AllocatorSam Silvestro, Hongyu Liu, Corey Crosser, Zhiqiang Lin 等CCS 2017 · 被引用 71 次
- MarkUs: Drop-in use-after-free prevention for low-level languagesSam Ainsworth, Timothy M. JonesS&P 2020 · 被引用 63 次
- Preventing Use-After-Free Attacks with Fast Forward AllocationBrian Wickman, Hong Hu, Insu Yun, Daehee Jang 等USENIX Security 2021 · 被引用 53 次
相关 Paper
- A Robust and Efficient Defense against Use-after-Free Exploits via Concurrent Pointer SweepingDaiping Liu, Mingwei Zhang, Haining WangCCS 2018 · 被引用 43 次
- PUMM: Preventing Use-After-Free Using Execution Unit PartitioningCarter Yagemann, Simon P. Chung, Brendan Saltaformaggio, Wenke LeeUSENIX Security 2023
- SwiftSweeper: Defeating Use-After-Free Bugs Using Memory Sweeper Without Stop-the-WorldJunho Ahn, Kanghyuk Lee, Chanyoung Park, Hyungon Moon 等S&P 2025
- Efficient Use-After-Free Prevention with Opportunistic Page-Level SweepingChanyoung Park, Hyungon MoonNDSS 2024
- FreeWill: Automatically Diagnosing Use-after-free Bugs via Reference Miscounting Detection on BinariesLiang He, Hong Hu, Purui Su, Yan Cai 等USENIX Security 2022
