FreeWill: Automatically Diagnosing Use-after-free Bugs via Reference Miscounting Detection on Binaries
Liang He, Hong Hu, Purui Su, Yan Cai, Zhenkai Liang
摘要
Memory-safety issues in operating systems and popular applications are still top security threats. As one widely exploited vulnerability, Use After Free (UAF) resulted in hundreds of new incidents every year. Existing bug diagnosis techniques report the locations that allocate or deallocate the vulnerable object, but cannot provide sufficient information for developers to reason about a bug or synthesize a correct patch. In this work, we identified incorrect reference counting as one common root cause of UAF bugs: if the developer forgets to increase the counter for a newly created reference, the program may prematurely free the actively used object, rendering other references dangling pointers. We call this problem reference miscounting. By proposing an omissionaware counting model, we developed an automatic method, FREEWILL, to diagnose UAF bugs. FREEWILL first reproduces a UAF bug and collects related execution trace. Then, it identifies the UAF object and related references. Finally, FREEWILL compares reference operations with our model to detect reference miscounting. We evaluated FREEWILL on 76 real-world UAF bugs and it successfully confirmed reference miscounting as root causes for 48 bugs and dangling usage for 18 bugs. FREEWILL also identified five null-pointer dereference bugs and failed to analyze five bugs. FREEWILL can complete its analysis within 15 minutes on average, showing its practicality for diagnosing UAF bugs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- NeuDep: neural binary memory dependence analysisKexin Pei, Dongdong She, Michael Wang, Scott Geng 等FSE 2022 · 被引用 8 次
- Detecting Kernel Memory Bugs through Inconsistent Memory Management Intention InferencesDinghao Liu, Zhipeng Lu, Shouling Ji, Kangjie Lu 等USENIX Security 2024 · 被引用 6 次
- PET: Prevent Discovered Errors from Being Triggered in the Linux KernelZicheng Wang, Yueqi Chen, Qingkai ZengUSENIX Security 2023
- Statically Discover Cross-Entry Use-After-Free Vulnerabilities in the Linux KernelHang Zhang, Jangha Kim, Chuhong Yuan, Zhiyun Qian 等NDSS 2025
- Uncovering the iceberg from the tip: Generating API Specifications for Bug Detection via Specification Propagation AnalysisMiaoqian Lin, Kai Chen, Yi Yang, Jinghua LiuNDSS 2025
它引用的顶会 Paper10
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang 等USENIX Security 2018 · 被引用 537 次
- Superset Disassembly: Statically Rewriting x86 Binaries Without HeuristicsErick Bauman, Zhiqiang Lin, Kevin W. HamlenNDSS 2018 · 被引用 112 次
- Oscar: A Practical Page-Permissions-Based Scheme for Thwarting Dangling PointersThurston H. Y. Dang, Petros Maniatis, David A. WagnerUSENIX Security 2017 · 被引用 77 次
- MarkUs: Drop-in use-after-free prevention for low-level languagesSam Ainsworth, Timothy M. JonesS&P 2020 · 被引用 63 次
- Preventing Use-After-Free Attacks with Fast Forward AllocationBrian Wickman, Hong Hu, Insu Yun, Daehee Jang 等USENIX Security 2021 · 被引用 53 次
相关 Paper
- CountDown: Refcount-guided Fuzzing for Exposing Temporal Memory Errors in Linux KernelShuangpeng Bai, Zhechang Zhang, Hong HuCCS 2024 · 被引用 4 次
- UAFSan: an object-identifier-based dynamic approach for detecting use-after-free vulnerabilitiesBinfa Gui, Wei Song, Jeff HuangISSTA 2021 · 被引用 9 次
- A Robust and Efficient Defense against Use-after-Free Exploits via Concurrent Pointer SweepingDaiping Liu, Mingwei Zhang, Haining WangCCS 2018 · 被引用 43 次
- Detecting Kernel Refcount Bugs with Two-Dimensional Consistency CheckingXin Tan, Yuan Zhang, Xiyu Yang, Kangjie Lu 等USENIX Security 2021 · 被引用 26 次
- MineSweeper: a "clean sweep" for drop-in use-after-free preventionMárton Erdos, Sam Ainsworth, Timothy M. JonesASPLOS 2022 · 被引用 13 次
