Practical Program Modularization with Type-Based Dependence Analysis

Practical Program Modularization with Type-Based Dependence Analysis
复制标题

DOI:
10.1109/sp46215.2023.10179412
复制
发表时间:
2023-05
期刊:
2023 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Kangjie Lu
Kangjie Lu
中科院分区:
其他
文献类型:
--
作者:
Kangjie Lu

文献摘要

相似文献

今天的软件程序正在膨胀,并且已经变得非常复杂。由于程序中的模块之间通常没有内部隔离,因此可以利用漏洞来破坏内存并控制整个程序。因此,程序模块化是一种很有前途的安全机制,它将复杂的程序分割成更小的模块,从而可以限制内存访问指令破坏不相关的模块。实现程序模块化的一般方法是依赖性分析,它确定指令是否独立于特定的代码或数据;如果是,它可以被模块化。不幸的是,复杂程序中的依赖分析通常被认为是不可行的,这是由于数据流分析中的问题,如未知的间接调用目标,指针别名和路径爆炸。因此,我们还没有看到实际的自动程序模块化依赖分析。本文提出了一个突破性的基于类型的依赖分析程序模块化(TyPM)。它的目标是确定程序中的哪些模块永远不能将某种类型的对象(包括引用)传递给内存访问指令;因此,由这些模块创建的这种类型的对象永远不能成为指令的有效目标。其思想是采用基于类型的分析来首先确定哪些类型的数据流可以在两个模块之间发生,然后相对于特定类型传递地解析存储器访问指令的所有依赖模块。这种方法避免了数据流分析,具有一定的实用性。我们基于TyPM开发了两个重要的安全应用程序:细化间接调用目标和保护关键数据结构。我们使用各种系统软件对TyPM进行了广泛的评估,包括OS内核、hypervisor、UEFI固件和浏览器。结果表明,平均而言,TyPM还将最先进技术产生的间接调用目标细化了31%-91%。TyPM还可以删除99.9%的内存写指令模块,以防止它们破坏Linux内核中的关键数据结构。
Today's software programs are bloating and have become extremely complex. As there is typically no internal isolation among modules in a program, a vulnerability can be exploited to corrupt the memory and take control of the whole program. Program modularization is thus a promising security mechanism that splits a complex program into smaller modules, so that memory-access instructions can be constrained from corrupting irrelevant modules. A general approach to realizing program modularization is dependence analysis which determines if an instruction is independent of specific code or data; and if so, it can be modularized. Unfortunately, dependence analysis in complex programs is generally considered infeasible, due to problems in data-flow analysis, such as unknown indirect-call targets, pointer aliasing, and path explosion. As a result, we have not seen practical automated program modularization built on dependence analysis.This paper presents a breakthrough—Type-based dependence analysis for Program Modularization (TyPM). Its goal is to determine which modules in a program can never pass a type of object (including references) to a memory-access instruction; therefore, objects of this type that are created by these modules can never be valid targets of the instruction. The idea is to employ a type-based analysis to first determine which types of data flows can take place between two modules, and then transitively resolve all dependent modules of a memory-access instruction, with respect to the specific type. Such an approach avoids the data-flow analysis and can be practical. We develop two important security applications based on TyPM: refining indirect-call targets and protecting critical data structures. We extensively evaluate TyPM with various system software, including an OS kernel, a hypervisor, UEFI firmware, and a browser. Results show that on average TyPM additionally refines indirect-call targets produced by the state of the art by 31%-91%. TyPM can also remove 99.9% of modules for memory-write instructions to prevent them from corrupting critical data structures in the Linux kernel.