AI 中文总结
本文提出新评估范式,对比Rust、Go等原生内存安全语言与组合后的C语言改造方案,发现分层C防御性能代价高、有架构不兼容问题,防护不及原生安全语言,呼吁转向整体比较评估框架以弥合工程决策缺口。
AI 中文摘要
尽管数十年的研究已为C语言开发出众多改造型内存安全防护机制,但这些机制几乎均被单独评估,仅针对特定漏洞类别。这种孤岛式评估范式导致开发者无法清晰了解,为实现全面安全而分层部署防御时会产生的累积性能开销、互操作性冲突及防护缺口。本文提出一种新的评估范式,将Rust、Go等原生内存安全语言与组合后的C语言改造方案进行基准测试。通过标准化跨语言任务,我们评估了最先进机制组合部署时的性能与防护权衡。结果表明,分层式C语言防御会产生累积且依赖工作负载的性能惩罚,可能存在根本性架构不兼容问题,且防护范围不及原生内存安全语言。这些发现揭示了一个关键的工程决策缺口:将安全特性回移植到C语言的真实成本对开发者而言是未知的。我们主张内存安全研究需发生根本性转变:从孤岛式评估转向整体、比较性框架,为在遗留代码库改造与迁移至现代安全语言之间的高风险选择提供依据。
英文摘要
While decades of research have produced numerous retrofitted memory-safety protections for C, these mechanisms are almost exclusively evaluated in isolation, targeting specific vulnerability classes. This siloed evaluation paradigm leaves practitioners without a clear understanding of the cumulative performance costs, interoperability conflicts, and protection gaps that arise when layering defenses to achieve comprehensive safety. This paper presents a new evaluation paradigm that benchmarks natively memory-safe languages like Rust and Go against compounded C retrofits. Using standardized cross-language tasks, we evaluate the performance and protection tradeoffs of state-of-the-art mechanisms when deployed in combination. Our results demonstrate that layered C defenses incur compounding and workload-dependent performance penalties, can suffer from fundamental architectural incompatibilities, and fall short of the protection scope provided by native memory-safe languages. These findings expose a critical engineering decision gap where the true cost of backporting safety to C remains hidden from practitioners. We argue for a fundamental shift in memory-safety research: moving away from isolated evaluation toward holistic, comparative frameworks that inform the high-stakes choice between retrofitting legacy codebases and migrating to modern, safe languages.