Control Flow and Pointer Integrity Enforcement in a Secure Tagged Architecture

Control Flow and Pointer Integrity Enforcement in a Secure Tagged Architecture
复制标题

DOI:
10.1109/sp46215.2023.10179416
复制
发表时间:
2023-05
期刊:
2023 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Ravi Theja Gollapudi;Gokturk Yuksek;David Demicco;Matthew Cole;Gaurav Kothari;Rohit Kulkarni;Xin Z
Ravi Theja Gollapudi;Gokturk Yuksek;David Demicco;Matthew Cole;Gaurav Kothari;Rohit Kulkarni;Xin Z
中科院分区:
其他
文献类型:
--
作者:
Ravi Theja Gollapudi;Gokturk Yuksek;David Demicco;Matthew Cole;Gaurav Kothari;Rohit Kulkarni;Xin Z

文献摘要

被引文献

相似文献

控制流攻击利用软件漏洞将控制流动转移到意外的路径中以最终执行攻击代码。本文探讨了指令和数据标记作为挫败此类控制流攻击的一般手段的使用,包括依赖违反指针完整性的攻击。使用特定类型的窄宽数据标签以及嵌入在二进制中的窄宽指令标签,促进了防止此类攻击所需的安全策略,从而导致实际上可行的解决方案。在缓存线中靠近其相应指令的共同定位指令标签消除了对指令标签访问的单独机制的需求。从编译器的分析阶段收集的信息已得到增强,并用于生成指令和数据标签。展示了由修改的LLVM编译器,改进的Linux OS支持标签和FPGA IMPLENT的CPU硬件原型,用于强制CFI,数据指针和代码指针完整性。通过适度的硬件增强功能,原型系统上的基准应用程序的执行时间被证明仅限于基线系统的低,单位数字,而无需标记。
Control flow attacks exploit software vulnerabilities to divert the flow of control into unintended paths to ultimately execute attack code. This paper explores the use of instruction and data tagging as a general means of thwarting such control flow attacks, including attacks that rely on violating pointer integrity. Using specific types of narrow-width data tags along with narrow-width instruction tags embedded within the binary facilitates the security policies required to protect against such attacks, leading to a practically viable solution. Co-locating instruction tags close to their corresponding instructions within cache lines eliminates the need for separate mechanisms for instruction tag accesses. Information gleaned from the analysis phase of a compiler is augmented and used to generate the instruction and data tags. A full-stack implementation that consists of a modified LLVM compiler, modified Linux OS support for tags and a FPGA-implemented CPU hardware prototype for enforcing CFI, data pointer and code pointer integrity is demonstrated. With a modest hardware enhancement, the execution time of benchmark applications on the prototype system is shown to be limited to low, single-digit percentages of a baseline system without tagging.