GuaNary: Efficient Buffer Overflow Detection In Virtualized Clouds Using Intel EPT-based Sub-Page Write Protection Support

GuaNary: Efficient Buffer Overflow Detection In Virtualized Clouds Using Intel EPT-based Sub-Page Write Protection Support
复制标题

DOI:
10.1145/3626787
复制
发表时间:
2023-12
期刊:
Proceedings of the ACM on Measurement and Analysis of Computing Systems
影响因子:
--
通讯作者:
Stella Bitchebe;Yves Kone;Pierre Olivier;Jalil Boukhobza;Yérom-David Bromberg;D. Hagimont;A. Tchana
Stella Bitchebe;Yves Kone;Pierre Olivier;Jalil Boukhobza;Yérom-David Bromberg;D. Hagimont;A. Tchana
中科院分区:
其他
文献类型:
--
作者:
Stella Bitchebe;Yves Kone;Pierre Olivier;Jalil Boukhobza;Yérom-David Bromberg;D. Hagimont;A. Tchana

文献摘要

相似文献

写缓冲区溢出是C/C++中一个广泛存在的内存安全漏洞,被报告为2022年和2023年的最大漏洞。安全内存分配器通常用于保护系统免受可能利用缓冲区溢出的攻击。现有的分配器主要依赖于两种类型的对策来防止或检测写溢出:金丝雀和保护页,每种在检测延迟和内存占用方面都有优点和缺点。对于虚拟化云应用程序,本文遵循了超管理程序(OoH)的趋势,并介绍了GuaNary,一个防止写溢出的安全防护,允许以低内存占用成本进行同步检测。OoH是2022年引入的一个新的虚拟化研究轴,倡导将虚拟化的硬件功能暴露给来宾操作系统,以便其进程可以利用它们。基于OoH原则,GuaNary利用Intel Sub-Page write Permission(SPP),这是一项最新的硬件虚拟化功能,允许以128 B(即子页)而不是4KB的粒度对来宾内存进行写保护。我们实现了一个软件栈,LeanGuard,它促进了使用GuaNary的新的安全分配器从虚拟机内部对SPP的利用。我们的评估表明,对于相同数量的受保护缓冲区,LeanGuard消耗的内存比SlimGuard少8.3倍,SlimGuard是最近最先进的安全分配器。此外,对于相同的内存消耗,LeanGuard允许保护比SlimGuard多25倍的缓冲区。
Write buffer overflow is a widespread and prevalent memory safety violation in C/C++, reported as the top vulnerability in 2022 and 2023. Secure memory allocators are generally used to protect systems against attacks that may exploit buffer overflows. Existing allocators mainly rely on two types of countermeasures to prevent or detect write overflows: canaries and guard pages, each with pros and cons in terms of detection latency and memory footprint. For virtualized cloud applications, this paper follows the Out of Hypervisor (OoH) trend and introduces GuaNary, a safety guard against write overflows, allowing synchronous detection at a low memory footprint cost. OoH is a new virtualization research axis introduced in 2022 advocating the exposure of hardware features for virtualization to the guest OS so that its processes can take advantage of them. Based on the OoH principle, GuaNary leverages Intel Sub-Page write Permission (SPP), a recent hardware virtualization feature that allows to write-protect guest memory at the granularity of 128B (namely, sub-page) instead of 4KB. We implement a software stack, LeanGuard, which promotes the utilization of SPP from inside virtual machines by new secure allocators that use GuaNary. Our evaluation shows that for the same number of protected buffers, LeanGuard consumes 8.3× less memory than SlimGuard, a recent state-of-art secure allocator. Further, for the same memory consumption, LeanGuard allows protecting 25× more buffers than SlimGuard.