Hardware-based Always-On Heap Memory Safety

Hardware-based Always-On Heap Memory Safety
复制标题

基于硬件的始终在线堆内存安全

DOI:
--
复制
发表时间:
2020
期刊:
Micro
影响因子:
--
通讯作者:
Hyesoon Kim
Hyesoon Kim
中科院分区:
--
文献类型:
--
作者:
Yonghae Kim;Jaekyu Lee;Hyesoon Kim

文献摘要

参考文献

被引文献

相似文献

由于在不安全的编程语言(如C和c++)中非法使用指针而导致的内存安全违规,已成为现代计算机系统的主要威胁。然而,实现低开销但健壮的运行时内存安全解决方案仍然具有挑战性。已经提出了各种基于硬件的机制,但是它们的重要硬件要求限制了它们的可行性,并且它们的性能开销太高,无法成为始终在线的解决方案。在本文中,我们提出了AOS,一种低开销的永远在线的堆内存安全解决方案,它实现了一种新的边界检查机制。我们发现现有边界检查方法的主要挑战是1)内存检查和元数据传播的额外指令开销以及2)复杂的元数据寻址。为了解决这些挑战,使用Arm PA原语,我们利用指针未使用的上位来存储键,并将其与指针地址一起传播,从而消除了传播开销。然后,我们使用嵌入键对散列边界表进行索引,以实现高效的元数据管理。我们还引入了一个微体系结构单元来消除对内存检查指令的需要。我们证明了AOS克服了上述所有挑战,并证明了它作为一种高效的运行时内存安全解决方案的可行性。我们对SPEC 2006工作负载的评估显示,平均性能开销为8.4%。
Memory safety violations, caused by illegal use of pointers in unsafe programming languages such as C and C++, have been a major threat to modern computer systems. However, implementing a low-overhead yet robust runtime memory safety solution is still challenging. Various hardware-based mechanisms have been proposed, but their significant hardware requirements have limited their feasibility, and their performance overhead is too high to be an always-on solution.In this paper, we propose AOS, a low-overhead always-on heap memory safety solution that implements a novel bounds-checking mechanism. We identify that the major challenges of existing bounds-checking approaches are 1) the extra instruction overhead for memory checking and metadata propagation and 2) the complex metadata addressing. To address these challenges, using Arm PA primitives, we leverage unused upper bits of a pointer to store a key and have it propagated along with the pointer address, eliminating propagation overhead. Then, we use the embedded key to index a hashed bounds table to achieve efficient metadata management. We also introduce a micro-architectural unit to remove the need for memory checking instructions. We show that AOS overcomes all the aforementioned challenges and demonstrate its feasibility as an efficient runtime memory safety solution. Our evaluation for SPEC 2006 workloads shows an 8.4% performance overhead on average.
CHERI Concentrate:实用的压缩功能
DOI: 10.1109/tc.2019.2914037
发表时间: 2019
影响因子: 3.7
作者:
Woodruff J
通讯作者: Woodruff J
DOI: 10.1145/3297858.3304017
发表时间: 2019-04
期刊: Proceedings of the Twenty-Fourth International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子: --
作者:
T. Zhang;Dongyoon Lee;Changhee Jung
通讯作者: T. Zhang;Dongyoon Lee;Changhee Jung