DMGuard: Safeguarding Kernels from Physical-Page Use-After-Free Vulnerabilities
Juhee Kim, Jaeyoung Chung, Dae R. Jeong, Byoungyoung Lee
摘要
Modern kernels depend on the integrity of page tables to enforce advanced security measures. Although these defenses have effectively mitigated various attacks including memory corruption, adversaries have shifted their focus to compromise the page table itself to bypass existing protections. Such threats are exacerbated by the rise of heterogeneous address translation domains including separate CPU, GPU, and IOMMU page tables, which impose heavy demands on synchronization and coherence management. When a virtual address remains mapped to a physical page that has already been freed or reallocated, attackers can exploit this to access arbitrary physical memory. We call this physical-page use-after-free, distinct from traditional heap use-after-free that operates on virtual addresses. In this paper, we present DMGuard, the first runtime mitigation that comprehensively addresses physical-page use-after-free vulnerabilities across diverse translation domains. DMGuard leverages a lightweight, lockless mechanism to manage a state machine of physical pages to ensure no dangling mappings exist in the page tables. Evaluation of DMGuard on Android devices demonstrates that it effectively blocks all known physical-page use-after-free vulnerabilities with negligible performance overheads, demonstrating the practicality and effectiveness against emerging attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper16
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris 等NDSS 2016 · 被引用 141 次
- SEIMI: Efficient and Secure SMAP-Enabled Intra-process Memory IsolationZhe Wang, Chenggang Wu, Mengyao Xie, Yinqian Zhang 等S&P 2020 · 被引用 37 次
- Page-Oriented Programming: Subverting Control-Flow Integrity of Commodity Operating System Kernels with Non-Writable Code PagesSeunghun Han, Seong-Joong Kim, Wook Shin, Byung Joon Kim 等USENIX Security 2024 · 被引用 9 次
- BUDAlloc: Defeating Use-After-Free Bugs by Decoupling Virtual Address Management from KernelJunho Ahn, Jaehyeon Lee, Kanghyuk Lee, Wooseok Gwak 等USENIX Security 2024 · 被引用 6 次
相关 Paper
- Preventing Use-After-Free Attacks with Fast Forward AllocationBrian Wickman, Hong Hu, Insu Yun, Daehee Jang 等USENIX Security 2021 · 被引用 53 次
- GHost in the Shell: A GPU-to-Host Memory Attack and its MitigationSihyun Roh, Woohyuk Choi, Jaeyoung Chung, Yoochan Lee 等S&P 2026 · 被引用 2 次
- PhantomMap: GPU-Assisted Kernel ExploitationJiayi Hu, Qi Tang, Xingkai Wang, Jinmeng Zhou 等NDSS 2026
- ViK: practical mitigation of temporal memory safety violations through object ID inspectionHaehyun Cho, Jinbum Park, Adam Oest, Tiffany Bao 等ASPLOS 2022 · 被引用 13 次
- FreeGuard: A Faster Secure Heap AllocatorSam Silvestro, Hongyu Liu, Corey Crosser, Zhiqiang Lin 等CCS 2017 · 被引用 71 次
