There are no files associated with this item.
Full metadata record
DC Field | Value | Language |
---|---|---|
dc.citation.conferencePlace | US | - |
dc.citation.endPage | 2387 | - |
dc.citation.startPage | 2373 | - |
dc.citation.title | ACM conference on Computer and communications security | - |
dc.contributor.author | Jeon, Yuseok | - |
dc.contributor.author | Biswas, P. | - |
dc.contributor.author | Carr, S. | - |
dc.contributor.author | Lee, B. | - |
dc.contributor.author | Payer, M. | - |
dc.date.accessioned | 2023-12-19T18:06:46Z | - |
dc.date.available | 2023-12-19T18:06:46Z | - |
dc.date.created | 2020-12-01 | - |
dc.date.issued | 2017-10-30 | - |
dc.description.abstract | Type confusion, often combined with use-after-free, is the main attack vector to compromise modern C++ software like browsers or virtual machines. Typecasting is a core principle that enables modularity in C++. For performance, most typecasts are only checked statically, i.e., the check only tests if a cast is allowed for the given type hierarchy, ignoring the actual runtime type of the object. Using an object of an incompatible base type instead of a derived type results in type confusion. Attackers abuse such type confusion issues to attack popular software products including Adobe Flash, PHP, Google Chrome, or Firefox. We propose to make all type checks explicit, replacing static checks with full runtime type checks. To minimize the performance impact of our mechanism HexType, we develop both low-overhead data structures and compiler optimizations. To maximize detection coverage, we handle specific object allocation patterns, e.g., placement new or reinterpret-cast which are not handled by other mechanisms. Our prototype results show that, compared to prior work, Hex-Type has at least 1.1-6.1 times higher coverage on Firefox benchmarks. For SPEC CPU2006 benchmarks with overhead, we show a 2-33.4 times reduction in overhead. In addition, HexType discovered 4 new type confusion bugs in Qt and Apache Xerces-C++. © 2017 author(s). | - |
dc.identifier.bibliographicCitation | ACM conference on Computer and communications security, pp.2373 - 2387 | - |
dc.identifier.doi | 10.1145/3133956.3134062 | - |
dc.identifier.issn | 1543-7221 | - |
dc.identifier.scopusid | 2-s2.0-85041443823 | - |
dc.identifier.uri | https://scholarworks.unist.ac.kr/handle/201301/48976 | - |
dc.language | 영어 | - |
dc.publisher | Association for Computing Machinery | - |
dc.title | HexType: Efficient detection of type confusion errors for C++ | - |
dc.type | Conference Paper | - |
dc.date.conferenceDate | 2017-10-30 | - |
Items in Repository are protected by copyright, with all rights reserved, unless otherwise indicated.
Tel : 052-217-1404 / Email : scholarworks@unist.ac.kr
Copyright (c) 2023 by UNIST LIBRARY. All rights reserved.
ScholarWorks@UNIST was established as an OAK Project for the National Library of Korea.