Back to Search Start Over

Towards Improved Mitigations for Two Attacks on Memory Safety

Authors :
Dang, Thurston Hou Yeen
Wagner, David1
Maniatis, Petros
Dang, Thurston Hou Yeen
Dang, Thurston Hou Yeen
Wagner, David1
Maniatis, Petros
Dang, Thurston Hou Yeen
Publication Year :
2017

Abstract

C, C++ and most other popular low-level languages delegate memory management to the programmer, frequently resulting in bugs. Accordingly, a longstanding problem in computer security is efficient, backwards-compatible prevention of the data and control-flow exploits that arise from writing past the end of a buffer or using memory after it has been freed.In the first part of this dissertation, we consider protection schemes against the most popular form of control-flow hijacking: return-oriented programming (ROP), which depends on misusing RET instructions. Control-flow defenses against ROP either use strict, expensive, but strong protection against redirected RET instructions with shadow stacks or other dual-stack schemes, or much faster but weaker protections without. We study the inherent overheads of shadow stack schemes (~10%). We then design a new scheme, the parallel shadow stack, with significantly less overhead (~3.5%) and better compatibility. Our measurements suggest it will not be easy to further improve software-only shadow stack performance on current x86 processors, due to inherent costs associated with RET and memory load/store instructions.Next, we consider defenses against heap use-after-free, which is an increasingly important class of memory safety errors. We show that, in principle, page permissions should be the most desirable approach. We then validate this experimentally by designing, implementing, and evaluating Oscar, a new protection scheme based on page permissions. Oscar does not require source code, is compatible with standard and custom memory allocators, works correctly with programs that fork, and performs favorably --- often by more than an order of magnitude --- compared to recent proposals: overall, it has similar or lower runtime overhead, and lower memory overhead than competing systems.Yesteryear's page-permissions-based allocators, including Oscar, all place one object per virtual page, to allow physical memory to be reclaimed

Details

Database :
OAIster
Notes :
application/pdf, English
Publication Type :
Electronic Resource
Accession number :
edsoai.on1287461125
Document Type :
Electronic Resource