HardsHeap: A Universal and Extensible Framework for Evaluating Secure Allocators

HardsHeap: A Universal and Extensible Framework for Evaluating Secure Allocators
复制标题

DOI:
10.1145/3460120.3484740
复制
发表时间:
2021-11
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Insu Yun;Woosun Song;Seunggi Min;Taesoo Kim
Insu Yun;Woosun Song;Seunggi Min;Taesoo Kim
中科院分区:
其他
文献类型:
--
作者:
Insu Yun;Woosun Song;Seunggi Min;Taesoo Kim

文献摘要

相似文献

安全分配器已被广泛研究以减轻堆漏洞。他们采用安全设计和随机机制来阻止或减轻堆利用。尽管进行了大量的研究工作,但安全分配器只能通过理论分析或预定义的数据集进行评估,这不足以有效地反映现实世界中强大的对手。在本文中,我们介绍了 HardsHeap,一种用于评估安全分配器的自动工具。 HardsHeap 的关键思想是使用随机测试(即模糊测试)来评估安全分配器。为了处理安全分配器的不同属性,HardsHeap 支持可扩展框架,从而可以轻松为每个属性编写验证逻辑。此外,HardsHeap 采用基于采样的测试,这使我们能够评估安全分配器中普遍存在的概率机制。为了消除 HardsHeap 结果中的冗余,我们设计了一种称为统计显着性增量调试 (SSDD) 的新技术,该技术将现有的增量调试扩展到随机可重现的测试用例。我们对 HardsHeap 进行了 10 个安全分配器的评估。因此,我们发现了 56 个有趣的测试用例,其中包括一些在安全分配器中处理大对象时不安全但被低估的行为。此外,我们还发现了 10 个实施错误。其中一个错误是安全分配器中的整数溢出,这使得它们比普通分配器更加无懈可击。我们的评估还表明,SSDD 成功地将测试用例平均减少了 37.2%,且不损失可重复性。
Secure allocators have been extensively studied to mitigate heap vulnerabilities. They employ safe designs and randomized mechanisms to stop or mitigate heap exploitation. Despite extensive research efforts, secure allocators can only be evaluated by with theoretical analysis or pre-defined data sets, which are insufficient to effectively reflect powerful adversaries in the real world. In this paper, we present HardsHeap, an automatic tool for evaluating secure allocators. The key idea of HardsHeap is to use random testing (i.e., fuzzing) to evaluate secure allocators. To handle the diverse properties of secure allocators, HardsHeap supports an extensible framework, making it easy to write a validation logic for each property. Moreover, HardsHeap employs sampling-based testing, which enables us to evaluate a probabilistic mechanism prevalent in secure allocators. To eliminate redundancy in findings from HardsHeap, we devise a new technique called Statistical Significance Delta Debugging (SSDD), which extends the existing delta debugging for stochastically reproducible test cases. We evaluated HardsHeap to 10 secure allocators. Consequently, we found 56 interesting test cases, including several unsecure yet underestimated behaviors for handling large objects in secure allocators. Moreover, we discovered 10 implementation bugs. One of the bugs is integer overflow in secure allocators, making them even more invulnerable than ordinary allocators. Our evaluation also shows that SSDD successfully reduces test cases by 37.2% on average without a loss of reproducibility.