Don't Waste My Efforts: Pruning Redundant Sanitizer Checks by Developer-Implemented Type Checks
Yizhuo Zhai, Zhiyun Qian, Chengyu Song, Manu Sridharan, Trent Jaeger, Paul L. Yu, Srikanth V. Krishnamurthy
摘要
Type confusion occurs when C or C++ code accesses an object after casting it to an incompatible type. The security impacts of type confusion vulnerabilities are significant, potentially leading to system crashes or even arbitrary code execution. To mitigate these security threats, both static and dynamic approaches have been developed to detect type confusion bugs. However, static approaches can suffer from excessive false positives, while existing dynamic approaches track type information for each object to enable safety checking at each cast, introducing a high runtime overhead. In this paper, we present a novel tool T-PRUNIFY to reduce the overhead of dynamic type confusion sanitizers. We observe that in large complex C++ projects, to prevent type confusion bugs, developers often add their own encoding of runtime type information (RTTI) into classes, to enable efficient runtime type checks before casts. T-PRUNIFY works by first identifying these custom RTTI in classes, automatically determining the relationship between field and method return values and the concrete types of corresponding objects. Based on these custom RTTI, T-PRUNIFY can identify cases where a cast is protected by developer-written type checks that guarantee the safety of the cast. Consequently, it can safely remove sanitizer instrumentation for such casts, reducing performance overhead. We evaluate T-PRUNIFY based on HexType, a state-of-the-art type confusion sanitizer that supports extensive C++ projects such as Google Chrome. Our findings demonstrate that our method significantly lowers HexType's average overhead by 25% to 75% in large C++ programs, marking a substantial enhancement in performance.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Anota: Identifying Business Logic Vulnerabilities via Annotation-Based SanitizationMeng Wang, Philipp Görz, Joschua Schilling, Keno Hassler 等NDSS 2026 · 被引用 4 次
- Type-Alias Analysis: Enabling LLVM IR with Accurate TypesJinmeng Zhou, Ziyue Pan, Wenbo Shen, Xingkai Wang 等ISSTA 2025 · 被引用 1 次
- SoK: Challenges and Paths Toward Memory Safety for eBPFKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson 等S&P 2025
- Protecting Source Code Privacy When Hunting Memory BugsJielun Wu, Bing Shui, Hongcheng Fan, Shengxin Wu 等ASE 2025
它引用的顶会 Paper5
- Stack Bounds Protection with Low Fat PointersGregory J. Duck, Roland H. C. Yap, Lorenzo CavallaroNDSS 2017 · 被引用 121 次
- TypeSan: Practical Type Confusion DetectionIstván Haller, Yuseok Jeon, Hui Peng, Mathias Payer 等CCS 2016 · 被引用 97 次
- HexType: Efficient Detection of Type Confusion Errors for C++Yuseok Jeon, Priyam Biswas, Scott A. Carr, Byoungyoung Lee 等CCS 2017 · 被引用 67 次
- SANRAZOR: Reducing Redundant Sanitizer Checks in C/C++ ProgramsJiang Zhang, Shuai Wang, Manuel Rigger, Pinjia He 等OSDI 2021 · 被引用 38 次
- The Taming of the Stack: Isolating Stack Data from Memory ErrorsKaiming Huang, Yongzhe Huang, Mathias Payer, Zhiyun Qian 等NDSS 2022
相关 Paper
- type++: Prohibiting Type Confusion with Inline Type InformationNicolas Badoux, Flavio Toffalini, Yuseok Jeon, Mathias PayerNDSS 2025
- Uncontained: Uncovering Container Confusion in the Linux KernelJakob Koschel, Pietro Borrello, Daniele Cono D'Elia, Herbert Bos 等USENIX Security 2023
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na 等S&P 2019 · 被引用 196 次
- Link-Time Optimization of Dynamic Casts in C++ ProgramsXufan Lu, Nuno P. LopesPLDI 2025 · 被引用 1 次
- Evaluating the Effectiveness of Memory Safety SanitizersEmanuel Q. Vintila, Philipp Zieris, Julian HorschS&P 2025
