Abstract
Control-flow integrity (CFI) is a strong and efficient defense mechanism against memory-corruption attacks. The practical versions of CFI, which have been integrated into compilers, employ static analysis to collect all possibly valid target functions of indirect calls. They are however less effective because the static analysis is imprecise. While more precise CFI techniques have been proposed, such as dynamic CFI, they are not yet practical due to issues on performance, compatibility, and deployability. We believe that to be practical, CFI based on static analysis is still the promising direction. However, these years have not seen much progress on the effectiveness of such practical CFI. This paper aims to boost the effectiveness of practical CFI by dramatically optimizing the target-function sets (aka equivalence class or EC) of indirect calls. We first identify two fundamental limitations that lead to the imprecision of static indirect-call analysis: incomplete field sensitivity due to variable field indexes and the unawareness of the origins of point-to targets. We then propose two novel analysis techniques, complete field sensitivity and origin awareness, which handle variable field indexes and distinguish target origins. The techniques dramatically reduce the size of target functions. To enforce the origin awareness, we further employ Intel Memory Protection Keys to safely store the origin information. We implement our techniques as a system called ECCut. The evaluation results show that compared to the mainline LLVM CFI, ECCut achieves a substantial reduction of 94.8% and 90.3% in the average and the largest EC sizes. While compared to the state-of-the-art origin-aware CFI (i.e., OS-CFI), ECCut reduces the average and the largest EC sizes by 90.2% and 89.3% respectively. Additionally, ECCut introduces an acceptable performance overhead (7.2% on average) observed across a comprehensive range of C/C++ benchmark tests in SPEC CPU2006, SPEC CPU2017, and six real-world applications.
| Original language | English (US) |
|---|---|
| Title of host publication | CCS 2024 - Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security |
| Publisher | Association for Computing Machinery, Inc |
| Pages | 4524-4538 |
| Number of pages | 15 |
| ISBN (Electronic) | 9798400706363 |
| DOIs | |
| State | Published - Dec 9 2024 |
| Event | 31st ACM SIGSAC Conference on Computer and Communications Security, CCS 2024 - Salt Lake City, United States Duration: Oct 14 2024 → Oct 18 2024 |
Publication series
| Name | CCS 2024 - Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security |
|---|
Conference
| Conference | 31st ACM SIGSAC Conference on Computer and Communications Security, CCS 2024 |
|---|---|
| Country/Territory | United States |
| City | Salt Lake City |
| Period | 10/14/24 → 10/18/24 |
Bibliographical note
Publisher Copyright:© 2024 Copyright held by the owner/author(s).
Keywords
- Complete field sensitivity
- Control-flow integrity
- Origin awareness
- Static analysis
Fingerprint
Dive into the research topics of 'Boosting Practical Control-Flow Integrity with Complete Field Sensitivity and Origin Awareness'. Together they form a unique fingerprint.Cite this
- APA
- Standard
- Harvard
- Vancouver
- Author
- BIBTEX
- RIS