CHEx86: Context-Sensitive Enforcement of Memory Safety via Microcode-Enabled Capabilities

CHEx86: Context-Sensitive Enforcement of Memory Safety via Microcode-Enabled Capabilities
复制标题

DOI:
10.1109/isca45697.2020.00068
复制
发表时间:
2020-05
期刊:
2020 ACM/IEEE 47th Annual International Symposium on Computer Architecture (ISCA)
影响因子:
--
通讯作者:
Rasool Sharifi;A. Venkat
Rasool Sharifi;A. Venkat
中科院分区:
其他
文献类型:
--
作者:
Rasool Sharifi;A. Venkat

文献摘要

相似文献

这项工作介绍了用于确保应用程序(包括遗产二进制文件)的CHEX86处理器体系结构,以针对针对时间和空间内存安全性漏洞(例如外部范围内访问),无需使用,免费,双倍的和双重的,无双重的和空间记忆安全漏洞,以实现各种安全性。通过在微码级别上启动代码,完全读取了完全下层的读取,仅访问源级符号信息,读取代码。此外,这项工作还提出了一种新颖的方案,用于在机器代码级别使用一组可配置的一组自动构造的规则在机器代码级别进行投机指针算术和指针运动,包括在内存中检测指针别名。该体系结构的表现优于地址消毒剂,地址消毒剂是一种基于软件的最先进的缓解措施,同时消除了与重新编译相关的移植,部署和验证成本。
This work introduces the CHEx86 processor architecture for securing applications, including legacy binaries, against a wide array of security exploits that target temporal and spatial memory safety vulnerabilities such as out-of-bounds accesses, use-after-free, double-free, and uninitialized reads, by instrumenting the code at the microcode-level, completely under-the-hood, with only limited access to source-level symbol information. In addition, this work presents a novel scheme for speculatively tracking pointer arithmetic and pointer movement, including the detection of pointer aliases in memory, at the machine code-level using a configurable set of automatically constructed rules. This architecture outperforms the address sanitizer, a state-of-the-art software-based mitigation by 59%, while eliminating porting, deployment, and verification costs that are invariably associated with recompilation.