PKRU-safe: automatically locking down the heap between safe and unsafe languages

PKRU-safe: automatically locking down the heap between safe and unsafe languages
复制标题

PKRU-safe:自动锁定安全和不安全语言之间的堆

DOI:
10.1145/3492321.3519582
复制
发表时间:
2022
期刊:
Proceedings of the Seventeenth European Conference on Computer Systems
影响因子:
--
通讯作者:
M. Franz
M. Franz
中科院分区:
--
文献类型:
--
作者:
Paul Kirth;Mitchel Dickerson;Stephen Crane;Per Larsen;Adrian Dabrowski;David Gens;Yeoul Na;Stijn Volckaert;M. Franz

文献摘要

参考文献

被引文献

相似文献

经过25年多的研究,内存安全违规仍然是现实世界软件安全漏洞的主要原因之一。像Rust这样的内存安全语言已经证明,编译器技术可以帮助开发人员编写高效的低级代码,而不会有内存损坏的风险。然而,许多内存安全语言仍然必须在一定程度上与不安全代码对接,这为攻击者利用系统不安全部分的内存损坏漏洞并破坏内存安全语言提供的安全保证打开了可能性。在本文中,我们提出了PKRU-SAFE,一种在混合语言环境中对不安全组件执行最小特权原则的自动化方法。PKRU-SAFE可确保不安全的(外部)代码不会损坏或以其他方式滥用安全语言组件专用的内存。我们的方法是自动化的,使用传统的编译器基础设施来有效地限制开发人员指定的组件的内存访问。PKRU-SAFE不需要对程序的原始数据流或执行模型进行任何修改。它可以被包含遗留代码的项目采用,只需很少的工作,只需要对项目的构建文件和依赖项进行少量更改,并为每个不受信任的库添加几行注释。我们将PKRU-Safe应用于Servo,这是最大的Rust项目之一,它拥有大约两百万行Rust代码(包括依赖项),以自动分区浏览器的堆,并保护其不安全的C/C++编写的JavaScript引擎。我们的详细评估表明,PKRU-SAFE能够阻止真实世界的攻击,通常没有可测量的开销,在我们最悲观的基准套件中,平均开销低于11.55%。由于该方法与语言无关,并且主要原型组件直接在LLVMIR上操作,因此将我们的技术应用于其他语言是简单的。
After more than twenty-five years of research, memory safety violations remain one of the major causes of security vulnerabilities in real-world software. Memory-safe languages, like Rust, have demonstrated that compiler technology can assist developers in writing efficient low-level code without the risk of memory corruption. However, many memory-safe languages still have to interface with unsafe code to some extent, which opens up the possibility for attackers to exploit memory-corruption vulnerabilities in the unsafe part of the system and subvert the safety guarantees provided by the memory-safe language. In this paper, we present PKRU-Safe, an automated method for enforcing the principle of least privilege on unsafe components in mixed-language environments. PKRU-Safe ensures that unsafe (external) code cannot corrupt or otherwise abuse memory used exclusively by the safe-language components. Our approach is automated using traditional compiler infrastructure to limit memory accesses for developer-designated components efficiently. PKRU-Safe does not require any modifications to the program's original data flows or execution model. It can be adopted by projects containing legacy code with minimal effort, requiring only a small number of changes to a project's build files and dependencies, and a few lines of annotations for each untrusted library. We apply PKRU-Safe to Servo, one of the largest Rust projects with approximately two million lines of Rust code (including dependencies) to automatically partition and protect the browser's heap from its JavaScript engine written in unsafe C/C++. Our detailed evaluation shows that PKRU-Safe is able to thwart real-world exploits, often without measurable overhead, and with a mean overhead under 11.55% in our most pessimistic benchmark suite. As the method is language agnostic and major prototype components operate directly on LLVM IR, applying our techniques to other languages is straightforward.
DOI: 10.1145/3243734.3243739
发表时间: 2018-05
期刊: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer
通讯作者: Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer