HeapSafe: Securing Unprotected Heaps in RISC-V

HeapSafe: Securing Unprotected Heaps in RISC-V
复制标题

DOI:
10.1109/vlsid2022.2022.00034
复制
发表时间:
2021-05
期刊:
2022 35th International Conference on VLSI Design and 2022 21st International Conference on Embedded Systems (VLSID)
影响因子:
--
通讯作者:
Asmit De;Swaroop Ghosh
Asmit De;Swaroop Ghosh
中科院分区:
其他
文献类型:
--
作者:
Asmit De;Swaroop Ghosh

文献摘要

相似文献

RISC-V是一种很有前途的开源架构,主要针对嵌入式系统。使用RISC-V工具链编译的程序可以在系统上以裸金属运行,因此可能容易受到几个内存损坏漏洞的攻击。在这项工作中,我们提出了HeapSafe,一个轻量级的硬件辅助堆缓冲区保护方案,以减轻堆溢出和使用后,免费的漏洞在RISC-V SoC。建议的计划标记与堆缓冲区的指针与元数据索引和强制标签传播常用的指针操作。HeapSafe硬件与内核解耦,设计为可配置协处理器,负责验证堆缓冲区访问。基准测试结果显示,性能开销为1.5倍,面积开销为1.59%,比软件保护快22%。我们进一步实现了一个异步验证设计HeapSafe-nb,它比同步HeapSafe提高了27%的性能。
RISC-V is a promising open-source architecture primarily targeted for embedded systems. Programs compiled using the RISC-V toolchain can run bare-metal on the system, and, as such, can be vulnerable to several memory corruption vulnerabilities. In this work, we present HeapSafe, a lightweight hardware assisted heap-buffer protection scheme to mitigate heap overflow and use-after-free vulnerabilities in a RISC-V SoC. The proposed scheme tags pointers associated with heap buffers with metadata indices and enforces tag propagation for commonly used pointer operations. The HeapSafe hardware is decoupled from the core and is designed as a configurable coprocessor and is responsible for validating the heap buffer accesses. Benchmark results show a 1.5X performance overhead and 1.59% area overhead, while being 22% faster than a software protection. We further implemented a HeapSafe-nb, an asynchronous validation design, which improves performance by 27% over the synchronous HeapSafe.