Position Paper: Towards a Hybrid Approach to Protect Against Memory Safety Vulnerabilities
Position Paper: Towards a Hybrid Approach to Protect Against Memory Safety Vulnerabilities
复制标题
DOI:
10.1109/secdev53368.2022.00020
复制
发表时间:
2021-06
期刊:
影响因子:
--
通讯作者:
A. Bhayat;L. Cordeiro;Giles Reger;F. Shmarov;Konstantin Korovin;T. Melham;Kaled Alshamrany;Mustafa A. Mustafa-Mustafa-A.-Mustafa-144411037;Pierre Olivier
中科院分区:
文献类型:
--
作者:
A. Bhayat;L. Cordeiro;Giles Reger;F. Shmarov;Konstantin Korovin;T. Melham;Kaled Alshamrany;Mustafa A. Mustafa-Mustafa-A.-Mustafa-144411037;Pierre Olivier
Memory corruption bugs continue to plague low-level systems software, generally written in unsafe programming languages. In order to detect and protect against such exploits, many pre- and post-deployment techniques exist. In this position paper, we propose and motivate the need for a hybrid approach for the protection against memory safety vulnerabilities, com-bining techniques that can identify the presence (and absence) of vulnerabilities pre-deployment with those that can detect and mitigate such vulnerabilities post-deployment. Our proposed hy-brid approach involves three layers: hardware runtime protection provided by capability hardware, software runtime protection provided by compiler instrumentation, and static analysis pro-vided by bounded model checking and symbolic execution. The key aspect of the proposed hybrid approach is that the protection offered is greater than the sum of its parts - the expense of post-deployment runtime checks is potentially reduced via information obtained during pre-deployment analysis. During pre-deployment analysis, static checking can be guided by runtime information.