Lune

USENIX Security2024顶会

RustSan: Retrofitting AddressSanitizer for Efficient Sanitization of Rust

Kyuwon Cho, Jongyoon Kim, Kha Dinh Duy, Hajeong Lim, Hojoon Lee

出版方
2024年份
7被引次数
4顶会引用

摘要

Rust is gaining traction as a safe systems programming language with its strong type and memory safety guarantees. However, Rust's guarantees are not infallible. The use of unsafe Rust, a subvariant of Rust, allows the programmer to temporarily escape the strict Rust language semantics to trade security for flexibility. Memory errors within unsafe blocks in Rust have far-reaching ramifications for the program's safety. As a result, the conventional dynamic memory error detection (e.g., fuzzing) has been adapted as a common practice for Rust and proved its effectiveness through a trophy case of discovered CVEs. RUSTSAN is a retrofitted design of AddressSanitizer (ASan) for efficient dynamic memory error detection of Rust programs. Our observation is that a significant portion of instrumented memory access sites in a Rust program compiled with ASan is redundant, as the Rust security guarantees can still be valid at the site. RUSTSAN identifies and instruments the sites that definitely or may undermine Rust security guarantees while lifting instrumentation on safe sites. To this end, RUSTSAN employs a cross-IR program analysis for accurate tracking of unsafe sites and also extends ASan's shadow memory scheme for checking non-uniform memory access validation necessary for Rust. We conduct a comprehensive evaluation of RUSTSAN in terms of detection capability and performance using 57 Rust crates. RUSTSAN successfully detected all 31 tested cases of CVE-issued memory errors. Also, RUSTSAN shows an average of 62.3% performance increase against ASan in general benchmarks that involved 20 Rust crates. In the fuzzing experiment with 6 crates, RUST-SAN marked an average of 23.52%, and up to 57.08% of performance improvement. * Corresponding author strict compile-time rules and lightweight runtime checking. Many new developments have adopted Rust as the main programming language [2, 4-8, 17, 21, 41]. Also, the inclusion of Rust infrastructure in the Linux kernel [2] was a landmark in the ongoing widespread adoption of Rust. However, Rust's safety guarantees are not achieved without a price. Rust draws the programmer's cooperation by imposing its strict language semantics. By doing so, the language design and the programmer together yield code whose memory safety can be validated by the compiler and minimal runtime checks. Rust's safety model can be too restrictive for certain use cases requiring fine-grained touch. For this reason, Rust provides a variant of itself called unsafe Rust that lives within a code block declared using the unsafe keyword. The unsafe Rust enjoys unconfined access to language semantics prohibited in Rust, such as raw pointer access and bypassing strict ownership enforcement [9] . The use of unsafe can be inevitable in certain programs (e.g., interfacing with low-level components) or a programmer's choice to trade safety for flexibility. Previous works have studied the common practices regarding using unsafe in Rust and their ramifications of using unsafe in Rust programs [22, 56] . The findings in these works indicate that the use of unsafe Rust is nearly the sole source of memory errors in Rust programs [56] . In response, researchers have proposed static analysis for discovering unsafe Rust memory errors [14, 26, 36, 37] and runtime isolation of safe Rust from unsafe in Rust programs [15, 31, 33, 38, 45] . Static analysis methods have limited detection capability on highly complex bugs or those that reveal themselves during runtime. Runtime isolation frameworks have laid the foundation for identifying insecure program subsets of Rust programs to protect safe Rust parts. Runtime isolation contains the impact of, rather than detect, the memory errors that stem from unsafe Rust. In addition, the proposed isolation solutions accompany hardware feature dependency (e.g., Memory Protection Key (MPK)) [15, 31] that hinders portability. Efforts are being made towards revamping the existing techniques to secure Rust amid the rise of safe languages. An efficient and

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext b4b4b8d6-37ea-4aa5-bf07-5ee6a493c1f8

引用它的顶会 Paper4

问问它们各自怎么用它

它引用的顶会 Paper14

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖