Prober: Practically Defending Overflows with Page Protection

Prober: Practically Defending Overflows with Page Protection
复制标题

DOI:
10.1145/3324884.3416533
复制
发表时间:
2020-09
期刊:
2020 35th IEEE/ACM International Conference on Automated Software Engineering (ASE)
影响因子:
--
通讯作者:
Hongyu Liu;Ruiqin Tian;Tongping Liu;Bin Ren
Hongyu Liu;Ruiqin Tian;Tongping Liu;Bin Ren
中科院分区:
其他
文献类型:
--
作者:
Hongyu Liu;Ruiqin Tian;Tongping Liu;Bin Ren

文献摘要

相似文献

即使经过几十年的研究,基于堆的溢出仍然没有完全解决。本文提出了一种新的系统Prober,该系统旨在检测和防止生产环境中的堆溢出。Prober基于对数十个真实错误的分析,利用了一个关键观察结果:所有堆溢出都与数组有关。基于这种观察,Prober只关注与数组相关的堆对象,而不是所有的堆对象。Prober在编译期间使用静态分析来标记所有易受影响的调用堆栈,然后在运行时使用页面保护来检测任何无效访问。除此之外,Prober将现有的多种方法整合在一起,以确保其检测的效率。总体而言,Prober带来的性能开销几乎可以忽略不计,平均为1.5%。Prober不仅及时阻止可能的攻击,还报告可能指导错误修复的错误指令。由于其有效性和低开销,Prober已做好部署准备。
Heap-based overflows are still not completely solved even after decades of research. This paper proposes Prober, a novel system aiming to detect and prevent heap overflows in the production environment. Prober leverages a key observation based on the analysis of dozens of real bugs: all heap overflows are related to arrays. Based on this observation, Prober only focuses on array-related heap objects, instead of all heap objects. Prober utilizes static analysis to label all susceptible call-stacks during the compilation, and then employs the page protection to detect any invalid accesses during the runtime. In addition to this, Prober integrates multiple existing methods together to ensure the efficiency of its detection. Overall, Prober introduces almost negligible performance overhead, with 1.5% on average. Prober not only stops possible attacks on time, but also reports the faulty instructions that could guide bug fixes. Prober is ready for deployment due to its effectiveness and low overhead.