Nalazite se na CroRIS probnoj okolini. Ovdje evidentirani podaci neće biti pohranjeni u Informacijskom sustavu znanosti RH. Ako je ovo greška, CroRIS produkcijskoj okolini moguće je pristupi putem poveznice www.croris.hr
izvor podataka: crosbi !

SoK: Secure Memory Allocation (CROSBI ID 706583)

Prilog sa skupa u zborniku | ostalo | međunarodna recenzija

Novković, Bojan ; Golub, Marin SoK: Secure Memory Allocation. 2021. str. 128-142

Podaci o odgovornosti

Novković, Bojan ; Golub, Marin

engleski

SoK: Secure Memory Allocation

Heap-related memory corruption vulnerabilities are a severe threat that continues to wreak havoc in widespread software despite a few decades of research. Research in hardening memory allocation yielded several proposed designs and a large number of techniques designed to mitigate common heap- related vulnerabilities. However, rigid performance requirements imposed by the majority of vulnerable workloads are a severe hindrance to the practical use of secure memory allocation techniques and systems. This paper aims to systematically analyze and classify all secure heap allocation techniques and systems implementing them, which emerged in the last two decades, and compare their performance to conventional systems. We provide a concise overview of heap-related vulnerabilities and construct a threat model to identify previously overlooked and unmitigated threats. We analyze the root causes of performance overheads observed in the existing literature and identify practical issues hindering the adoption of secure memory allocation systems in practice. We conduct fine-grained and coarse-grained benchmarks on real-life workloads and well-known benchmark suites to compare and analyze the overall performance of secure memory allocation systems to conventional ones. Using the aforementioned benchmark results, we compare different designs of secure memory allocation systems and provide guidelines for striking a balance between security and performance in future designs.

Memory allocation ; Systems security ; Memory safety

nije evidentirano

nije evidentirano

nije evidentirano

nije evidentirano

nije evidentirano

nije evidentirano

Podaci o prilogu

128-142.

2021.

objavljeno

Podaci o matičnoj publikaciji

Podaci o skupu

20th International Conference on Cryptology And Network Security

predavanje

13.12.2021-15.12.2021

Beč, Austrija

Povezanost rada

Računarstvo