InstaGuard: Instantly Deployable Hot-patches for Vulnerable System Programs on Android
Yaohui Chen, Yuping Li, Long Lu, Yueh-Hsun Lin, Hayawardh Vijayakumar, Zhi Wang, Xinming Ou
摘要
Hot-patches, easier to develop and faster to deploy than permanent patches, are used to timely (and temporarily) block exploits of newly discovered vulnerabilities while permanent patches are being developed and tested. Researchers recently proposed to apply hot-patching techniques to system programs on Android as a quick mitigation against critical vulnerabilities. However, existing hot-patching techniques, though widely used in conventional computers, are rarely adopted by Android OS or device vendors in reality. Our study uncovers a major hurdle that prevents existing hot-patching methods from being effective on mobile devices: after being developed, hot-patches for mobile devices have to go through lengthy compatibility tests that Android device partners impose on all system code updates. This testing and release process can take months, and therefore, erase the key benefit of hot-patches (i.e., quickly deployable). We propose InstaGuard, a new approach to hot-patch for mobile devices that allows for instant deployment of patches (i.e., "carrier-passthrough") and fast patch development for device vendors. Unlike existing hot-patching techniques, InstaGuard avoids injecting new code to programs being patched. Instead, it enforces instantly updatable rules that contain no code (i.e., no carrier test is needed) to block exploits of unpatched vulnerabilities in a timely fashion. When designing InstaGuard, we overcame two major challenges that previous hot-patching methods did not face. First, since no code addition is allowed, InstaGuard needs a rule language that is expressive enough to mitigate various kinds of vulnerabilities and efficient to be enforced on mobile devices. Second, rule generation cannot require special skills or much efforts from human users. We designed a new language for hot-patches and an enforcement mechanism based on the basic debugging primitives supported by ARM CPUs. We also built RuleMaker, a tool for automatically generating rules for InstaGuard based on high-level, easy-to-write vulnerability descriptions. We have implemented InstaGuard on Google Nexus 5X phones. To demonstrate the coverage of InstaGuard, we show that InstaGuard can handle all critical CVEs from Android Security Bulletins reported in 2016. We also conduct unit tests using critical vulnerabilities from 4 different categories. On average, InstaGuard increases program memory footprint by 1.69% and slows down program execution by 2.70%, which are unnoticeable to device users in practice.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- Automating Patching of Vulnerable Open-Source Software Versions in Application BinariesRuian Duan, Ashish Bijlani, Yang Ji, Omar Alrawi 等NDSS 2019 · 被引用 63 次
- PDiff: Semantic-based Patch Presence Testing for Downstream KernelsZheyue Jiang, Yuan Zhang, Jun Xu, Qi Wen 等CCS 2020 · 被引用 54 次
- Undo Workarounds for Kernel BugsSeyed Mohammadjavad Seyed Talebi, Zhihao Yao, Ardalan Amiri Sani, Zhiyun Qian 等USENIX Security 2021 · 被引用 27 次
- BlueSWAT: A Lightweight State-Aware Security Framework for Bluetooth Low EnergyXijia Che, Yi He, Xuewei Feng, Kun Sun 等CCS 2024 · 被引用 10 次
- Save the Bruised Striver: A Reliable Live Patching Framework for Protecting Real-World PLCsMing Zhou, Haining Wang, Ke Li, Hongsong Zhu 等EuroSys 2024 · 被引用 9 次
它引用的顶会 Paper2
相关 Paper
- BScout: Direct Whole Patch Presence Test for Java ExecutablesJiarun Dai, Yuan Zhang, Zheyue Jiang, Yingtian Zhou 等USENIX Security 2020
- Automatic Hot Patch Generation for Android KernelsZhengzi Xu, Yulong Zhang, Longri Zheng, Liangzhao Xia 等USENIX Security 2020
- AutoPatch: Automated Generation of Hotpatches for Real-Time Embedded DevicesMohsen Salehi, Karthik PattabiramanCCS 2024 · 被引用 3 次
- RapidPatch: Firmware Hotpatching for Real-Time Embedded DevicesYi He, Zhenhua Zou, Kun Sun, Zhuotao Liu 等USENIX Security 2022
- Dynamic Vulnerability Patching for Heterogeneous Embedded Systems Using Stack Frame ReconstructionMing Zhou, Xupu Hu, Zhihao Wang, Haining Wang 等CCS 2025 · 被引用 1 次
