MarkUs: Drop-in use-after-free prevention for low-level languages

MarkUs: Drop-in use-after-free prevention for low-level languages
复制标题

DOI:
10.1109/sp40000.2020.00058
复制
发表时间:
2020-05
期刊:
2020 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
S. Ainsworth;Timothy M. Jones
S. Ainsworth;Timothy M. Jones
中科院分区:
其他
文献类型:
--
作者:
S. Ainsworth;Timothy M. Jones

文献摘要

被引文献

相似文献

无用的漏洞遇到了用低级语言(例如C ++)编写的软件,成为最频繁的剥削软件错误类别之一。并通过将数据重新分配给他们,然后使用错误的重用来控制程序,以获取对应用程序的控制,并可能采用各种技术来处理各种技术,以便利用该数据。这些漏洞通常具有令人难以置信的高性能或内存开销,尤其是在最坏的情况下。我们设计了Markus,一种记忆分配器,可以防止低开销的这种形式的攻击,即使在分配和内存下也足以在真实软件中部署 - 我们的情况。标记我们遇到的那些,以检查是否可以从当前分配的任何位置访问隔离数据。 。 Spec CPU2006的低水平语言的临时安全性平均为1.1×,最大速度仅为2倍,最新的最新情况大大改善。
Use-after-free vulnerabilities have plagued software written in low-level languages, such as C and C++, becoming one of the most frequent classes of exploited software bugs. Attackers identify code paths where data is manually freed by the programmer, but later incorrectly reused, and take advantage by reallocating the data to themselves. They then alter the data behind the program’s back, using the erroneous reuse to gain control of the application and, potentially, the system. While a variety of techniques have been developed to deal with these vulnerabilities, they often have unacceptably high performance or memory overheads, especially in the worst case.We have designed MarkUs, a memory allocator that prevents this form of attack at low overhead, sufficient for deployment in real software, even under allocation- and memory-intensive scenarios. We prevent use-after-free attacks by quarantining data freed by the programmer and forbidding its reallocation until we are sure that there are no dangling pointers targeting it. To identify these we traverse live-objects accessible from registers and memory, marking those we encounter, to check whether quarantined data is accessible from any currently allocated location. Unlike garbage collection, which is unsafe in C and C++, MarkUs ensures safety by only freeing data that is both quarantined by the programmer and has no identifiable dangling pointers. The information provided by the programmer’s allocations and frees further allows us to optimise the process by freeing physical addresses early for large objects, specialising analysis for small objects, and only performing marking when sufficient data is in quarantine. Using MarkUs, we reduce the overheads of temporal safety in low-level languages to 1.1× on average for SPEC CPU2006, with a maximum slowdown of only 2×, vastly improving upon the state-of-the-art.