Skip to main navigation Skip to search Skip to main content

Control Flow and Pointer Integrity Enforcement in a Secure Tagged Architecture

  • Ravi Theja Gollapudi
  • , Gokturk Yuksek
  • , David Demicco
  • , Matthew Cole
  • , Gaurav Kothari
  • , Rohit Kulkarni
  • , Xin Zhang
  • , Kanad Ghose
  • , Aravind Prakash
  • , Zerksis Umrigar
  • State University of New York Binghamton University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

9 Scopus citations

Abstract

Control flow attacks exploit software vulnerabilities to divert the flow of control into unintended paths to ultimately execute attack code. This paper explores the use of instruction and data tagging as a general means of thwarting such control flow attacks, including attacks that rely on violating pointer integrity. Using specific types of narrow-width data tags along with narrow-width instruction tags embedded within the binary facilitates the security policies required to protect against such attacks, leading to a practically viable solution. Co-locating instruction tags close to their corresponding instructions within cache lines eliminates the need for separate mechanisms for instruction tag accesses. Information gleaned from the analysis phase of a compiler is augmented and used to generate the instruction and data tags. A full-stack implementation that consists of a modified LLVM compiler, modified Linux OS support for tags and a FPGA-implemented CPU hardware prototype for enforcing CFI, data pointer and code pointer integrity is demonstrated. With a modest hardware enhancement, the execution time of benchmark applications on the prototype system is shown to be limited to low, single-digit percentages of a baseline system without tagging.

Original languageEnglish
Title of host publicationProceedings - 44th IEEE Symposium on Security and Privacy, SP 2023
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages2974-2989
Number of pages16
ISBN (Electronic)9781665493369
DOIs
StatePublished - 2023
Event44th IEEE Symposium on Security and Privacy, SP 2023 - Hybrid, San Francisco, United States
Duration: May 22 2023May 25 2023

Publication series

NameProceedings - IEEE Symposium on Security and Privacy
Volume2023-May

Conference

Conference44th IEEE Symposium on Security and Privacy, SP 2023
Country/TerritoryUnited States
CityHybrid, San Francisco
Period05/22/2305/25/23

Keywords

  • Control Flow Integrity
  • Hardware security
  • Pointer Integrity
  • Security and privacy policies
  • Security architectures

Fingerprint

Dive into the research topics of 'Control Flow and Pointer Integrity Enforcement in a Secure Tagged Architecture'. Together they form a unique fingerprint.

Cite this