CHERIvoke

CHERIvoke
复制标题

奇瑞沃克

DOI:
10.1145/3352460.3358288
复制
发表时间:
2019
期刊:
--
影响因子:
--
通讯作者:
Xia H
Xia H
中科院分区:
--
文献类型:
--
作者:
Xia H

文献摘要

相似文献

低级语言中缺乏时间安全性导致了释放后使用漏洞的流行。这些攻击在数量和严重程度上甚至超过了臭名昭著的违反空间安全的缓冲区溢出漏洞。能力寻址可以通过强制指针的边界和使指针不可伪造来直接强制C语言的空间安全性。然而,一个有效的解决方案,强大的时间存储器的安全性仍然难以捉摸。CHERI是一个架构扩展,提供硬件能力寻址,看到显着的商业和开源的兴趣。我们表明,CHERI功能可以作为一个基础,使低成本的堆临时安全,促进过时的指针撤销,因为功能,使精确和有效的识别和无效的指针,即使使用不安全的语言,如C。我们开发CHERIvoke,确定性和快速扫描撤销的技术,以执行CHERI系统的时间安全。CHERIvoke在周期性地使用一个小的阴影映射来在一次内存扫描中撤销所有悬挂指针之前,对释放的数据进行重新排序,并在性能和堆增长之间提供可调的权衡。我们使用高性能x86处理器评估此类系统的性能,并进一步分析检查其主要管理费用。当配置25%的堆大小开销时,我们发现CHERIvoke实现了低于5%的平均执行时间开销,远低于传统垃圾收集,撤销或页表系统的开销。
A lack of temporal safety in low-level languages has led to an epidemic of use-after-free exploits. These have surpassed in number and severity even the infamous buffer-overflow exploits violating spatial safety. Capability addressing can directly enforce spatial safety for the C language by enforcing bounds on pointers and by rendering pointers unforgeable. Nevertheless, an efficient solution for strong temporal memory safety remains elusive.CHERI is an architectural extension to provide hardware capability addressing that is seeing significant commercial and open-source interest. We show that CHERI capabilities can be used as a foundation to enable low-cost heap temporal safety by facilitating out-of-date pointer revocation, as capabilities enable precise and efficient identification and invalidation of pointers, even when using unsafe languages such as C. We develop CHERIvoke, a technique for deterministic and fast sweeping revocation to enforce temporal safety on CHERI systems. CHERIvoke quarantines freed data before periodically using a small shadow map to revoke all dangling pointers in a single sweep of memory, and provides a tunable trade-off between performance and heap growth. We evaluate the performance of such a system using high-performance x86 processors, and further analytically examine its primary overheads. When configured with a heap-size overhead of 25%, we find that CHERIvoke achieves an average execution-time overhead of under 5%, far below the overheads associated with traditional garbage collection, revocation, or page-table systems.