Back to Search Start Over

Position Paper: Towards a Hybrid Approach to Protect Against Memory Safety Vulnerabilities

Authors :
Kaled Alshmrany
Ahmed Bhayat
Franz Braube
Lucas Cordeiro
Konstantin Korovin
Tom Melham
Mustafa A. Mustafa
Pierre Olivier
Giles Reger
Fedor Shmarov
Source :
2022 IEEE Secure Development Conference (SecDev).
Publication Year :
2022
Publisher :
IEEE, 2022.

Abstract

Memory corruption bugs continue to plague lowlevel systems software, generally written in unsafe programming languages. In order to detect and protect against such exploits, many pre- and post-deployment techniques exist. In this position paper, we propose and motivate the need for a hybrid approach for the protection against memory safety vulnerabilities, combining techniques that can identify the presence (and absence) of vulnerabilities pre-deployment with those that can detect and mitigate such vulnerabilities post-deployment. Our proposed hybrid approach involves three layers: hardware runtime protection provided by capability hardware, software runtime protection provided by compiler instrumentation, and static analysis provided by bounded model checking and symbolic execution. The key aspect of the proposed hybrid approach is that the protection offered is greater than the sum of its parts – the expense of postdeployment runtime checks is potentially reduced via information obtained during pre-deployment analysis. During pre-deployment analysis, static checking can be guided by runtime information.

Details

Database :
OpenAIRE
Journal :
2022 IEEE Secure Development Conference (SecDev)
Accession number :
edsair.doi.dedup.....9900c154b92105b51deee67cb5ec840e
Full Text :
https://doi.org/10.1109/secdev53368.2022.00020