HerQules: securing programs via hardware-enforced message queues

HerQules: securing programs via hardware-enforced message queues
复制标题

DOI:
10.1145/3445814.3446736
复制
发表时间:
2021-04
期刊:
Proceedings of the 26th ACM International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子:
--
通讯作者:
Daming D. Chen;Wen Shih Lim;Mohammad Bakhshalipour;Phillip B. Gibbons;J. Hoe;Bryan Parno
Daming D. Chen;Wen Shih Lim;Mohammad Bakhshalipour;Phillip B. Gibbons;J. Hoe;Bryan Parno
中科院分区:
其他
文献类型:
--
作者:
Daming D. Chen;Wen Shih Lim;Mohammad Bakhshalipour;Phillip B. Gibbons;J. Hoe;Bryan Parno

文献摘要

相似文献

许多计算机程序使用不安全的指针直接操作内存,这可能会引入内存安全错误。作为回应,过去的工作开发了各种运行时防御措施,包括内存安全检查,以及旨在防止攻击者获得程序控制权的非执行内存、影子堆栈和控制流完整性(CFI)等缓解措施。然而,基于软件的设计通常需要更新进程内运行时元数据以最大限度地提高准确性,这很难准确、高效和安全地完成。基于硬件的细粒度指令监控通过在专用硬件中维护元数据避免了这一问题,但存在设计复杂性高和需要重大的微体系结构更改的问题。在本文中,我们提出了一种替代方案,它增加了一种快速的基于硬件的仅附加进程间通信(IPC)原语AppendWrite,该原语使被监控程序能够将执行事件的日志传输到运行在不同进程中的验证器,依赖于进程间内存保护进行隔离。我们展示了如何以非常低的成本使用FPGA或硬件实现AppendWite。使用这个原语,我们设计了HerQules(HQ),这是一个通过编译器插装自动执行基于完整性的执行策略的框架。总部通过并发将程序执行与策略检查分离,在不影响安全性的情况下减少了关键路径上的开销。我们在多个基准测试套件上进行了控制流完整性的案例研究,并证明了HQ-CFI在正确性、有效性和性能方面与以前的工作相比有了显著的提高。
Many computer programs directly manipulate memory using unsafe pointers, which may introduce memory safety bugs. In response, past work has developed various runtime defenses, including memory safety checks, as well as mitigations like no-execute memory, shadow stacks, and control-flow integrity (CFI), which aim to prevent attackers from obtaining program control. However, software-based designs often need to update in-process runtime metadata to maximize accuracy, which is difficult to do precisely, efficiently, and securely. Hardware-based fine-grained instruction monitoring avoids this problem by maintaining metadata in special-purpose hardware, but suffers from high design complexity and requires significant microarchitectural changes. In this paper, we present an alternative solution by adding a fast hardware-based append-only inter-process communication (IPC) primitive, named AppendWrite, which enables a monitored program to transmit a log of execution events to a verifier running in a different process, relying on inter-process memory protections for isolation. We show how AppendWrite can be implemented using an FPGA or in hardware at very low cost. Using this primitive, we design HerQules (HQ), a framework for automatically enforcing integrity-based execution policies through compiler instrumentation. HQ reduces overhead on the critical path by decoupling program execution from policy checking via concurrency, without affecting security. We perform a case study on control-flow integrity against multiple benchmark suites, and demonstrate that HQ-CFI achieves a significant improvement in correctness, effectiveness, and performance compared to prior work.