Static Detection of TOCTOU Bugs Caused by Kernel Races
Gui-Dong Han, Jia-Ju Bai, Qiu-Ji Chen, Jiqiang Lu
摘要
The TOCTOU (Time Of Check to Time Of Use) bug is a well-known security issue in kernel code, because it bypasses security checks and leads to unexpected behaviors that can cause serious problems like system crashes and privilege escalation. According to our study on Linux kernel patches, kernel race is the most common root cause of kernel TOCTOU bugs. However, due to the complexity of kernel concurrency logic and non-determinism of thread scheduling, there is still no systematic approach that focuses on detecting TOCTOU bugs caused by kernel races. In this paper, we design KERAT, the first systematic static approach for detecting TOCTOU bugs caused by kernel races. Indeed, such TOCTOU bugs are introduced by atomicity violations about the check-use operations of specific shared variables. Thus, KERAT performs bug detection by statically mining and checking the atomicity rules about shared variables from kernel code. Specifically, KERAT has two key techniques: (1) an atomicity-rule mining method to effectively identify which lock should protect the check-use operations of which shared variable; and (2) a state-based validation strategy to detect TOCTOU bugs that violate the mined atomicity rules based on state machines encoding of common bug patterns. We have evaluated KERAT on Linux-6.8 and FreeBSD-14.1, and found 351 real bugs. Among these bugs, 287 are identified as harmful, and 65 of them have been confirmed by kernel developers. 10 bugs have received CVE IDs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper21
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee 等S&P 2019 · 被引用 202 次
- Krace: Data Race Fuzzing for Kernel File SystemsMeng Xu, Sanidhya Kashyap, Hanqing Zhao, Taesoo KimS&P 2020 · 被引用 131 次
- Precise and Scalable Detection of Double-Fetch Bugs in OS KernelsMeng Xu, Chenxiong Qian, Kangjie Lu, Michael Backes 等S&P 2018 · 被引用 95 次
- How Double-Fetch Situations turn into Double-Fetch Vulnerabilities: A Study of Double Fetches in the Linux KernelPengfei Wang, Jens Krinke, Kai Lu, Gen Li 等USENIX Security 2017 · 被引用 66 次
- Check It Again: Detecting Lacking-Recheck Bugs in OS KernelsWenwen Wang, Kangjie Lu, Pen-Chung YewCCS 2018 · 被引用 49 次
相关 Paper
- LR-Miner: Static Race Detection in OS Kernels by Mining Locking RulesTuo Li, Jia-Ju Bai, Gui-Dong Han, Shi-Min HuUSENIX Security 2024 · 被引用 6 次
- Precise Detection of Kernel Data Races with Probabilistic Lockset AnalysisGabriel Ryan, Abhishek Shah, Dongdong She, Suman JanaS&P 2023
- Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints InferencesKangjie Lu, Aditya Pakki, Qiushi WuUSENIX Security 2019 · 被引用 97 次
- Diagnosing Kernel Concurrency Failures with AITIADae R. Jeong, Minkyu Jung, Yoochan Lee, Byoungyoung Lee 等EuroSys 2023 · 被引用 3 次
- On the TOCTOU Problem in Remote AttestationIvan De Oliveira Nunes, Sashidhar Jakkamsetti, Norrathep Rattanavipanon, Gene TsudikCCS 2021 · 被引用 2 次
