Position Paper: Towards a Hybrid Approach to Protect Against Memory Safety Vulnerabilities

Position Paper: Towards a Hybrid Approach to Protect Against Memory Safety Vulnerabilities
复制标题

DOI:
10.1109/secdev53368.2022.00020
复制
发表时间:
2021-06
期刊:
2022 IEEE Secure Development Conference (SecDev)
影响因子:
--
通讯作者:
A. Bhayat;L. Cordeiro;Giles Reger;F. Shmarov;Konstantin Korovin;T. Melham;Kaled Alshamrany;Mustafa A. Mustafa-Mustafa-A.-Mustafa-144411037;Pierre Olivier
A. Bhayat;L. Cordeiro;Giles Reger;F. Shmarov;Konstantin Korovin;T. Melham;Kaled Alshamrany;Mustafa A. Mustafa-Mustafa-A.-Mustafa-144411037;Pierre Olivier
中科院分区:
其他
文献类型:
--
作者:
A. Bhayat;L. Cordeiro;Giles Reger;F. Shmarov;Konstantin Korovin;T. Melham;Kaled Alshamrany;Mustafa A. Mustafa-Mustafa-A.-Mustafa-144411037;Pierre Olivier

文献摘要

相似文献

内存损坏错误继续困扰着低级系统软件,这些软件通常用不安全的编程语言编写。为了检测和防范此类攻击,存在许多部署前和部署后技术。在这份立场文件中,我们建议并鼓励需要一种针对内存安全漏洞的混合保护方法,将可以在部署前识别漏洞的存在(和不存在)的技术与那些可以在部署后检测和缓解此类漏洞的技术相结合。我们提出的混合方法包括三个层次:能力硬件提供的硬件运行时保护,编译器插桩提供的软件运行时保护,以及有界模型检测和符号执行提供的静态分析。建议的混合方法的关键方面是提供的保护大于其各部分的总和-部署后运行时检查的费用可能会通过在部署前分析期间获得的信息而减少。在部署前分析期间,静态检查可以由运行时信息指导。
Memory corruption bugs continue to plague low-level systems software, generally written in unsafe programming languages. In order to detect and protect against such exploits, many pre- and post-deployment techniques exist. In this position paper, we propose and motivate the need for a hybrid approach for the protection against memory safety vulnerabilities, com-bining techniques that can identify the presence (and absence) of vulnerabilities pre-deployment with those that can detect and mitigate such vulnerabilities post-deployment. Our proposed hy-brid approach involves three layers: hardware runtime protection provided by capability hardware, software runtime protection provided by compiler instrumentation, and static analysis pro-vided by bounded model checking and symbolic execution. The key aspect of the proposed hybrid approach is that the protection offered is greater than the sum of its parts - the expense of post-deployment runtime checks is potentially reduced via information obtained during pre-deployment analysis. During pre-deployment analysis, static checking can be guided by runtime information.