Present but Unreachable: Reducing Persistentlatent Secrets in HotSpot JVM
Present but Unreachable: Reducing Persistentlatent Secrets in HotSpot JVM
复制标题
存在但无法访问:减少 HotSpot JVM 中的持久潜在秘密
DOI:
--
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
D. Wallach
中科院分区:
文献类型:
--
作者:
Adam Pridgen;S. Garfinkel;D. Wallach
The two most popular Java platforms that use the HotSpot Java Virtual Machine (JVM) are Oracle and OpenJDK. The HotSpot JVM automatically manages application memory for the developer using generational garbage collection (GC). Unfortunately, this managed memory fails to give developers the power to adequately sanitize sensitive data in objects and defend against memory disclosure attacks, i.e., attackers who can read the memory of a process containing Java objects. This problem stems from two design flaws in the GC tasks. First, the generational GC allows more than one copy of an object to exist in multiple heaps, even though they are unreachable. Second, when objects become garbage, they’re not sanitized or zeroed by the garbage collector; they survive until the memory is reused for a new object. Even if a developer wants to explicitly sanitize critical data, such as cryptographic keys for closed network connections, there are no manual mechanisms for this activity because the data is out of the developers reach. Consequently, this sensitive data can be extracted from garbage after applying object reconstruction techniques to the heap. For this paper, we show that up to 40% of the observed TLS encryption keys can be recovered from a Java heap using Oracle’s TLS 1.2 implementation. This paper also shows how modest GC changes reduce the amount of recoverable data, albeit with performance overheads as high as 50% in the worst case.