HeapSafe: Securing Unprotected Heaps in RISC-V
HeapSafe: Securing Unprotected Heaps in RISC-V
复制标题
DOI:
10.1109/vlsid2022.2022.00034
复制
发表时间:
2021-05
期刊:
影响因子:
--
通讯作者:
Asmit De;Swaroop Ghosh
中科院分区:
文献类型:
--
作者:
Asmit De;Swaroop Ghosh
RISC-V is a promising open-source architecture primarily targeted for embedded systems. Programs compiled using the RISC-V toolchain can run bare-metal on the system, and, as such, can be vulnerable to several memory corruption vulnerabilities. In this work, we present HeapSafe, a lightweight hardware assisted heap-buffer protection scheme to mitigate heap overflow and use-after-free vulnerabilities in a RISC-V SoC. The proposed scheme tags pointers associated with heap buffers with metadata indices and enforces tag propagation for commonly used pointer operations. The HeapSafe hardware is decoupled from the core and is designed as a configurable coprocessor and is responsible for validating the heap buffer accesses. Benchmark results show a 1.5X performance overhead and 1.59% area overhead, while being 22% faster than a software protection. We further implemented a HeapSafe-nb, an asynchronous validation design, which improves performance by 27% over the synchronous HeapSafe.