Oscar: A Practical Page-Permissions-Based Scheme for Thwarting Dangling Pointers
Thurston H. Y. Dang, Petros Maniatis, David A. Wagner
摘要
Using memory after it has been freed opens programs up to both data and control-flow exploits. Recent work on temporal memory safety has focused on using explicit lock-and-key mechanisms (objects are assigned a new lock upon allocation, and pointers must have the correct key to be dereferenced) or corrupting the pointer values upon free(). Placing objects on separate pages and using page permissions to enforce safety is an older, wellknown technique that has been maligned as too slow, without comprehensive analysis. We show that both old and new techniques are conceptually instances of lockand-key, and argue that, in principle, page permissions should be the most desirable approach. We then validate this insight experimentally by designing, implementing, and evaluating Oscar, a new protection scheme based on page permissions. Unlike prior attempts, Oscar does not require source code, is compatible with standard and custom memory allocators, and works correctly with programs that fork. Also, Oscar performs favorably -often by more than an order of magnitude -compared to recent proposals: overall, it has similar or lower runtime overhead, and lower memory overhead than competing systems. Explicit lock-and-key: changing the lock e.g., Implicit lock-and-key: revoking the keys e.g., Implicit lock-and-key: changing the lock e.g., Instrumentation CETS DangNull/FreeSentry Electric Fence malloc () Allocate lock address; Issue key; Set lock Register pointer Syscall to create virtual page Simple ptr arithmetic: p+=2 No cost General ptr arithmetic: p=q+1 Propagate lock address and key Update ptr registration No cost Pointer dereference: *p Check key vs. lock value (at lock address) No cost <TLB and memory pressure> free () Deallocate lock address Invalidate pointers Syscall to disable virtual page No application source needed Needs source + recompilation Yes; Req'd by Dhurjati&Adve Physical memory overhead O(# pointers) O(# pointers) O(# objects)
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper33
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na 等S&P 2019 · 被引用 196 次
- Enforcing Unique Code Target Property for Control-Flow IntegrityHong Hu, Chenxiong Qian, Carter Yagemann, Simon Pak Ho Chung 等CCS 2018 · 被引用 142 次
- Unikraft: fast, specialized unikernels the easy waySimon Kuenzer, Vlad-Andrei Badoiu, Hugo Lefeuvre, Sharan Santhanam 等EuroSys 2021 · 被引用 116 次
- Cornucopia: Temporal Safety for CHERI HeapsNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Sam Ainsworth 等S&P 2020 · 被引用 71 次
- MarkUs: Drop-in use-after-free prevention for low-level languagesSam Ainsworth, Timothy M. JonesS&P 2020 · 被引用 63 次
相关 Paper
- Fat Pointers for Temporal Memory Safety of CJie Zhou, John Criswell, Michael HicksOOPSLA 2023 · 被引用 17 次
- MineSweeper: a "clean sweep" for drop-in use-after-free preventionMárton Erdos, Sam Ainsworth, Timothy M. JonesASPLOS 2022 · 被引用 13 次
- Top of the Heap: Efficient Memory Error Protection of Safe Heap ObjectsKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson 等CCS 2024 · 被引用 3 次
- ViK: practical mitigation of temporal memory safety violations through object ID inspectionHaehyun Cho, Jinbum Park, Adam Oest, Tiffany Bao 等ASPLOS 2022 · 被引用 13 次
- Preventing Use-After-Free Attacks with Fast Forward AllocationBrian Wickman, Hong Hu, Insu Yun, Daehee Jang 等USENIX Security 2021 · 被引用 53 次
