发表机构
Polytechnique Montreal(蒙特利尔高等理工学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
MallocSan通过LD_PRELOAD和指针高位嵌入对象标识符,实现无需源码的堆内存安全检测,性能优于Valgrind,并有效发现真实漏洞。
AI 中文摘要
内存损坏错误仍然是C和C++软件中高危漏洞的主要原因。然而,确定性检测仍然难以部署:基于编译器的消毒器需要源代码并控制构建流程,硬件辅助方案依赖于特定平台,而动态二进制翻译可能带来数量级的性能下降。本文介绍了MallocSan,一种针对原生、可能闭源的x86-64 Linux应用程序的堆消毒器,它不需要源代码访问、重新编译或专用硬件。MallocSan通过LD_PRELOAD拦截内存分配,并在每个受保护指针的未使用高位中嵌入对象标识符。解引用由此产生的非规范指针会在违规指令处触发故障,MallocSan在运行时解码并修补该指令,以便后续执行完全在用户空间进行每对象边界检查。无法修补的位置回退到处理程序内模拟或单步执行,而可选的配置文件引导过程会离线重写频繁执行的残余位置。MallocSan还将基于身份的检查扩展到向量收集/分散指令,并支持策略范围的覆盖。在七个SPEC CPU 2017基准测试中,MallocSan在五个上优于Valgrind Memcheck,相对于原生执行的几何平均执行时间因子为4.82倍,而Memcheck为18.55倍,同时在两个评估的多线程工作负载(644.nab_s和pigz)上保持了显著的并行扩展。在范围内的Juliet测试中,MallocSan检测到所有植入的违规,并且在良好执行中没有误报。它还检测了真实世界应用程序中的堆缓冲区错误,包括LibTIFF的tiffcrop工具中已知的单字节过度读取。
英文摘要
Memory-corruption errors remain a leading cause of high-impact vulnerabilities in C and C++ software. Deterministic detection, however, remains difficult to deploy: compiler-based sanitizers require source code and control of the build pipeline, hardware-assisted schemes depend on specific platforms, and dynamic binary translation can impose order-of-magnitude slowdowns. This paper presents MallocSan, a heap sanitizer for native, potentially closed-source x86-64 Linux applications that requires no source access, recompilation, or specialized hardware. MallocSan interposes on memory allocation through LD_PRELOAD and embeds an object identifier in the unused high bits of each protected pointer. Dereferencing the resulting noncanonical pointer faults at the offending instruction, which MallocSan decodes and patches at runtime so that subsequent executions perform per-object bounds checks entirely in userspace. Sites that cannot be patched fall back to in-handler emulation or single-stepping, while an optional profile-guided pass rewrites frequently executed residual sites offline. MallocSan also extends identity-based checking to vector gather/scatter instructions and supports policy-scoped coverage. Across seven SPEC CPU 2017 benchmarks, MallocSan outperforms Valgrind Memcheck on five, with a geometric-mean execution-time factor of 4.82x relative to native execution, compared with 18.55x for Memcheck, while preserving substantial parallel scaling on both evaluated multithreaded workloads: 644.nab_s and pigz. On the in-scope Juliet tests, MallocSan detects all seeded violations with no false reports on the good executions. It also detects heap-buffer errors in real-world applications, including a known one-byte overread in LibTIFF's tiffcrop utility.
Comments28 pages. Submitted to ACM TOSEM; under review