Sticky Tags: Efficient and Deterministic Spatial Memory Error Mitigation using Persistent Memory Tags
Floris Gorter, Taddeus Kroes, Herbert Bos, Cristiano Giuffrida
摘要
Spatial memory errors such as buffer overflows still rank among the top vulnerabilities in C/C++ programs. Despite much research in the area, the performance overhead of (even partial) mitigations is still too high for practical adoption. To reduce the cost, recent solutions are shifting towards hardware-assisted techniques such as Arm’s Memory Tagging Extension (MTE). Unfortunately, state-of-the-art MTE solutions incur high overhead due to frequent memory (re)tagging, especially on the stack. Moreover, they rely on the secrecy of random memory tags and offer probabilistic security guarantees.In this paper, we first provide evidence that random tagging offers limited protection as attackers can deduce the memory tags by means of speculative probing. We then present StickyTags, a deterministic MTE solution that efficiently mitigates bounded spatial memory errors. By organizing the stack and heap layout into per-size-class regions, we can apply persistent memory tags to each region in a predetermined pattern. Hence, the memory tags need only be initialized once, after which they can be reused by objects of the same size class. This eliminates the need for costly memory retagging and allows for a fixed, round-robin assignment of the tags, surrounding every object with large implicit spatial guards. While the size of such guards is bounded by the 4-bit MTE entropy (16 tags), the protection is efficient and deterministic. Indeed, we show StickyTags significantly outperforms existing solutions with realistic runtime overheads for practical adoption (≤ 4% on SPEC CPU2006), while fully mitigating 7 out of 8 spatial CVEs evaluated by a recent probabilistic MTE solution.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- Voodoo: Memory Tagging, Authenticated Encryption, and Error Correction through MAGICLukas Lamster, Martin Unterguggenberger, David Schrammel, Stefan MangardUSENIX Security 2024 · 被引用 5 次
- Sharing is leaking: blocking transient-execution attacks with core-gapped confidential VMsCharly Castes, Andrew BaumannASPLOS 2024 · 被引用 2 次
- Segue & ColorGuard: Optimizing SFI Performance and Scalability on Modern ArchitecturesShravan Narayan, Tal Garfinkel, Evan Johnson, Zachary Yedidia 等ASPLOS 2025 · 被引用 1 次
- SpecASan: Mitigating Transient Execution Attacks Using Speculative Address SanitizationSaber Ganjisaffar, Esmaeil Mohmmadian Koruyeh, Jason Zellmer, Hodjat Asghari Esfeden 等ISCA 2025 · 被引用 1 次
- NanoTag: Systems Support for Efficient Byte-Granular Overflow Detection on ARM MTEMingkai Li, Hang Ye, Joseph Devietti, Suman Jana 等S&P 2026 · 被引用 1 次
它引用的顶会 Paper27
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- ASLR on the Line: Practical Cache Attacks on the MMUBen Gras, Kaveh Razavi, Erik Bosman, Herbert Bos 等NDSS 2017 · 被引用 276 次
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na 等S&P 2019 · 被引用 196 次
- Grand Pwning Unit: Accelerating Microarchitectural Attacks with the GPUPietro Frigo, Cristiano Giuffrida, Herbert Bos, Kaveh RazaviS&P 2018 · 被引用 178 次
- Robust Website Fingerprinting Through the Cache Occupancy ChannelAnatoly Shusterman, Lachlan Kang, Yarden Haskal, Yosef Meltser 等USENIX Security 2019 · 被引用 159 次
相关 Paper
- Tiktag: Breaking ARM's Memory Tagging Extension with Speculative ExecutionJuhee Kim, Jinbum Park, Sihyeon Roh, Jaeyoung Chung 等S&P 2025
- MTSan: A Feasible and Practical Memory Sanitizer for Fuzzing COTS BinariesXingman Chen, Yinghao Shi, Zheyu Jiang, Yuan Li 等USENIX Security 2023
- QuickSafe: Targeted Hardening Against Memory CorruptionJohannes Blaser, Floris Gorter, Klaus von Gleissenthall, Herbert BosS&P 2026
- BASTAG: Byte-level Access Control on Shared Memory using ARM Memory Tagging ExtensionJunseung You, Jiwon Seo, Kyeongryong Lee, Yeongpil Cho 等CCS 2025
- Beyond Tag Collision: Cluster-based Memory Management for Tag-based SanitizersMengfei Xie, Yan Lin, Hongtao Wu, Jianming Fu 等CCS 2025
