Apparatus and method for enhancing hardware-assisted memory safety
By combining branch target instruction protection and memory coloring protection methods, the problems of memory security and call flow integrity in computing devices are solved, and low-overhead full memory security and call flow integrity are achieved, which is suitable for mobile communication devices, etc.
Patent Information
- Application Number
- CN201980072126.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-03-12
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2039-03-12
AI Technical Summary
It is difficult for existing technologies to achieve full memory security and call flow integrity for computing devices without incurring high performance overhead, especially against return-to-libc and data-oriented programming attacks.
By combining branch target instruction protection and memory coloring protection between the processor and memory, the memory area is colored with an inaccessible color value and the color value is switched during function calls and returns, ensuring the hard coding of the coloring routine and the protection of branch target instruction.
It achieves near-full memory security and call flow integrity while maintaining low computational and memory usage overhead, reducing the risk of ROP attacks and is suitable for mobile communication devices, etc.
Smart Images

Figure CN112970019B_ABST
Abstract
Description
Technical Field
[0001] Aspects of the disclosed embodiments relate to mobile computing devices, and more particularly, to software security within mobile computing devices. Background Art
[0002] For the past decade, memory security in computer processors has been a focus for both attackers and defenders. Attackers have developed malware and rootkits that exploit code overwrite and data execution, such as by exploiting buffer overrun vulnerabilities, to compromise computing devices. Protection features such as Write-XOR-Execute (W^X) or, more generally, Data Execution Prevention (DEP), have mitigated most of the harmful effects of these attacks. In response, attackers are developing newer "return to libc," or more generally, "return-oriented programming" (ROP) and "data-oriented programming" (DOP) attacks that target DEP's protections.
[0003] Current approaches to improving memory safety focus on enhancing call flow integrity. This can be achieved through hardware methods, such as pointer validation available in some ARM architectures, hardware-supported shadow stack tracking for call tracking (something Intel is researching), and pure software solutions. However, these protection methods generally fail to guarantee memory safety beyond the call flow. Furthermore, many solutions incur significant performance overhead, sometimes as high as 400%. For many applications, these solutions are insufficient or impractical.
[0004] Some research efforts are focused on building hardware platforms for memory safety. One such effort is the CHERI (Capability Hardware Enhanced RISC Instructions) project at the University of Cambridge. CHERI introduces so-called fat pointers to the MIPS architecture, combining pointer integrity with memory segmentation. These features can be used to implement architectures for memory safety. However, these approaches are still in the early stages of research and are not yet generally applicable.
[0005] It would therefore be desirable to provide methods and apparatus that address at least some of the problems discussed above. Summary of the Invention
[0006] The disclosed embodiments aim to provide an improved method and apparatus for enhancing near-full memory safety and call flow integrity within a computing device while incurring little computational or memory overhead. This object is achieved by the subject matter of the independent claims. Further advantageous modifications can be found in the dependent claims.
[0007] In a first aspect, the above and further objects and advantages are achieved by an apparatus. The apparatus includes a processor coupled to a memory, wherein the processor and the memory are configured to provide branch target instruction protection and memory coloring protection. The processor is configured to color a first memory region associated with a first function using an inaccessible color value and branch to a second function, calling the second function from the first function. When executing within the second function, the processor is configured to color a second memory region associated with the second function using a second color value, perform an operation on the second memory region, and color the second memory region using the inaccessible color value. The processor then returns control to the first function and colors the first memory region using the first color value. The first color value, the second color value, and the inaccessible color value each represent a different color value. The coloring includes branching to a coloring routine, wherein the coloring routine includes a basic block that begins with a single branch target instruction. A calling routine is identified and authorized by coloring, the memory region associated with the calling routine is colored using a hard-coded memory color value, and a return is made to the calling routine. The coloring, combined with BTI, ensures near-full memory security and call flow integrity within the apparatus.
[0008] According to the first aspect, in a first possible implementation of the apparatus, the shading routine is located in an execute-only memory area, and the processor is configured to prevent writing to the execute-only memory area. Protecting the shading routine from modification can prevent malicious applications from controlling the shading and thereby accessing confidential or sensitive information.
[0009] According to the first aspect, in one possible implementation of the apparatus, the first memory area and the second memory area are allocated in a read / write portion of a memory and include at least one of a stack frame and a heap area. The processor is configured to prevent execution of data in the first memory area or the second memory area. Memory security is advantageously applicable to all types of memory spaces and is not limited to stack protection.
[0010] In one possible implementation of the apparatus, one or more stack parameters are passed from the first function to the second function, the one or more stack parameters being colored using a third color value. The third color value is different from either the inaccessible color value or the first color value, and the processor is configured to read and / or write the one or more stack parameters. The color used for the stack parameters is different from the color used by the first or second function, thereby isolating the parameters from other portions of the code.
[0011] In a possible implementation form of the apparatus, the second stack frame has one or more storage objects stored therein, each of the one or more storage objects being colored with a different color value. The processor is configured to read from and / or write to the one or more storage objects. Using a smaller granularity, such as a single storage object, improves security because an attack on a colored memory region provides less data access.
[0012] In a possible implementation form of the apparatus, the second function comprises a plurality of basic blocks, a storage object associated with each basic block being colored with a different color value. Using a smaller granularity, such as a single basic block, improves security because an attack on a colored memory region provides less data access.
[0013] In a possible implementation form, program instructions associated with an application are colored with a fourth color value, and all routines associated with software libraries accessed by the application are colored with a fifth color value. The fourth color value is different from the fifth color value, and the processor is configured to execute the application. Coloring the software libraries differently from the rest of the application code protects the application from the libraries and does not incur unnecessary development overhead.
[0014] In a possible implementation form, the second memory region comprises a stack frame, and the coloring the second memory region with the non-accessible color value comprises the processor resetting the second memory region to zero. Resetting the memory region to zero permanently deletes all sensitive data that can have been stored therein.
[0015] In a possible implementation form, the apparatus comprises a mobile communication device. Given the increasing use of banking, payment and personal information applications stored on mobile communication devices, proximity to full memory security and call flow integrity is particularly important for mobile communication devices.
[0016] In a second aspect, the above and further objects and advantages are achieved through a computer-implemented method, wherein the computer is configured to provide branch target instruction protection and memory coloring protection. The method comprises: coloring a first memory region associated with a first function using an inaccessible color value; branching to a second function; coloring a second memory region associated with the second function using a second color value; and performing an operation on the second memory region based on the second function. The method then colors the second memory region using the inaccessible color value; returns to the first function; and colors the first memory region using the first color value. The first color value, the second color value, and the inaccessible color value each comprise different color values. Coloring comprises: branching to a coloring routine, wherein the coloring routine comprises a single basic block beginning with a branch target instruction. A calling routine is identified and authorized through coloring, a memory region associated with the calling routine is colored using a hard-coded memory color value, and a return is made to the calling routine. The coloring, combined with BTI, ensures memory security and call flow integrity within the device.
[0017] In a first possible implementation form of the method, the shading routine is located in an execute-only memory area. Storing the shading routine in the execute-only memory area prevents an attacker from controlling the shading by modifying the shading routine.
[0018] In one possible implementation of the method, one or more stack parameters are passed from the first function to the second function, and the one or more stack parameters are colored using a third color value. The third color value is different from any of the inaccessible color value, the first color value, and the second color value. Coloring the parameters differently from any of the first function or the second function allows the parameters to be controlled independently of memory access associated with either function.
[0019] In one possible implementation of the method, one or more memory objects are stored in the second stack frame, and each of the one or more memory objects is colored using a different color value. This reduces the risk by limiting the amount of data accessible to an attacker attacking a specific memory region and thereby reducing the size of the colored memory region.
[0020] In one possible implementation of the method, the second function includes a plurality of basic blocks, and a storage object associated with each basic block is colored using a different color value. Using a different memory color for each basic block limits the data available to an attacker attacking the basic block.
[0021] In a third aspect, the above and further objects and advantages are achieved by a computer program product comprising non-transitory computer program instructions which, when executed by a processor, cause the processor to perform the method of the second aspect.
[0022] These and other aspects, implementations, and advantages of the exemplary embodiments will become apparent from the embodiments described herein when considered in conjunction with the accompanying drawings. It should be understood, however, that such description and drawings are for illustrative purposes only and are not intended to limit the present invention; reference should be made to the appended claims for any limitations thereto. Additional aspects and advantages of the present invention will be set forth in the description that follows, and some will be apparent from the description or may be learned by practice of the present invention. Furthermore, aspects and advantages of the present invention may be realized and obtained by any of the instrumentalities or combinations particularly pointed out in the appended claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In the following detailed description of the present disclosure, the present invention will be explained in more detail with reference to example embodiments shown in the accompanying drawings, in which:
[0024] Figure 1 A block diagram illustrating a computing device for providing near full memory security provided by aspects of the disclosed embodiments is shown;
[0025] Figure 2 A code overview of the mechanisms provided by aspects of the disclosed embodiments for providing near full memory safety is shown;
[0026] Figure 3 A flowchart illustrating an exemplary method for providing memory protection and call flow integrity in a computing device provided by aspects of the disclosed embodiments is shown;
[0027] Figure 4 A flow chart illustrating an exemplary shading routine for securely shading a memory region provided by aspects of the disclosed embodiments is shown. DETAILED DESCRIPTION
[0028] Now refer to Figure 1, shown is a block diagram of an apparatus 100 for providing near-full memory security according to aspects of the disclosed embodiments. The apparatus 100 is suitable for use with a variety of general-purpose computing devices, such as mobile communication devices, smartphones, tablet computers, phablets, laptop computers, or other computing devices that would benefit from improved memory security. The apparatus 100 includes a processor 150 communicatively coupled to a computer memory 152. The memory 152 can be any suitable type of computer-readable and writable memory, such as RAM, DRAM, or other types of physical memory. The memory 152 can be managed by the processor 150 or by other memory management-enabled hardware and software that works with the processor 150 to beneficially manage the computer memory 152.
[0029] As will be described further below, near-full memory safety and call flow integrity can be achieved through novel use of hardware features supported by device 100. These features contribute to security and can protect device 100 from malware attacks, including computational hardware that supports write-XOR-execute (W^X) protection, memory coloring, and branch target indication (BTI) mechanisms.
[0030] refer to Figure 1 and 2 In one embodiment, the processor 150 and the memory 152 are configured to provide branch target instruction protection and memory coloring protection. For example, the processor 150 is configured to color a first memory region 216 associated with a first function 202 using an inaccessible color value 220, branch 226 to a second function 208, color a second memory region 218 associated with the second function 206 using a second color value 250, and call 248 the second function 208 from the first function 202. An operation (242) is performed on the second memory region 218, the second memory region 218 is colored using the inaccessible color value 220, a return 228 is made to the first function 202, and the first memory region 216 is colored using the first color value 252. The first color value 252, the second color value 250, and the inaccessible color value 220 each include different color values.
[0031] In one embodiment, the coloring includes branching to a shading routine 204, 206, 210, and 212, wherein the shading routine includes a basic block that begins with a single branch target instruction, identifies and authorizes a calling routine, colors a memory region associated with the calling routine using a hard-coded color value, and returns to the calling routine.
[0032] To aid understanding, certain features of the disclosed embodiments will be described with reference to the ARMv8.5 processor architecture and features. The ARMv8.5 architecture is a reduced instruction set computer (RISC) architecture developed by ARM HOLDINGS pic. References to the ARMv8.5 architecture or other specific processor or architecture are provided herein solely to aid understanding. Those skilled in the art will readily recognize that the embodiments presented herein can be advantageously employed within other suitable computing devices, which can include alternative implementations of the above-listed protection features, without departing from the spirit and scope of the present disclosure.
[0033] The device 100 incorporates a security feature sometimes referred to as write- xor- execute (W^X) or data-execution prevention. W^X is a memory protection method in which each page in memory is either writable or executable, but not both. Without W^X protection, a program can exploit a software flaw, such as a buffer overflow flaw, to take control of the processor 150. W^X protection, sometimes referred to as data protection, prevents such attacks.
[0034] In the device 100, executable program instructions or executable code are loaded into a memory region that is being executed by an application can execute but cannot write to or modify. These execute-only memory regions are referred to herein as code spaces. During application execution, other memory regions are reserved for data or variables that are expected to be modified or have their values changed. These memory regions can be referred to as data spaces. W^X allows instructions stored in code spaces to be executed, but a processing exception is generated if an attempt is made to write to a code space (i.e., an execute-only code space). Similarly, a processing exception is generated if a program attempts to execute instructions read from a data space (i.e., a data space that can be written to but not executed).
[0035] The term “processing exception” as used herein refers to a way of changing the program or flow of execution so that the processor 150 can properly handle the exceptional condition. For example, if a program attempts to write to a code space, a hardware interrupt mechanism can be used to generate a processing exception.
[0036] Code generation time or compile time refers to the time at which program code is generated. Program code can be generated, for example, when a compiler is used to generate program code from a high-level language, or when a programmer manually crafts program code. The generated program code is loaded into code space when the application is executed in the computing device. Certain data values or constants can be set at code generation time and stored in code space along with the executable instructions. Values that are set at code generation time and stored in code space are referred to herein as hard-coded values or predetermined values. The intent is that the predetermined values never change during the execution of the application. By storing these predetermined values in code space, the W^X protection mechanism implemented in the device 100 will ensure that the predetermined values remain unchanged throughout the execution of the application.
[0037] The device 100 supports a memory safety feature known as memory coloring or memory tagging. With memory coloring, a memory block can be associated or tagged with a certain value, referred to as a color value or tag. Each memory block, sometimes referred to as a granule, is tagged with a particular value, referred to herein as a color value. The size or number of bytes in each memory block is referred to as the tag granularity. When memory is allocated, a memory management unit or other computing device selects a color value and associates that color value with the allocated memory. The selected color value is also associated with the memory pointer returned to the application that requested the memory allocation. Each time memory is accessed, such as through a load or store operation, the color value associated with the memory pointer is compared to the color value associated with the memory being accessed. The processor 150 or other memory management component in the device 100 is used to generate a processing exception when the pointer color and the memory color do not match.
[0038] The number of bits used for each color, referred to as the tag size, should be large enough to allow a sufficient number of different color values (e.g., 4 bits allows 16 different values), but small enough to be easily handled in hardware and software. For example, the tag size can be configured to fit in the high unused bits of a pointer, such as an 8-bit or 16-bit pointer. The selection of the tag granularity is a tradeoff between the tag size, alignment requirements, and hardware configuration.
[0039] The detection of temporal or spatial defects or other memory violations through the use of memory coloring is probabilistic and based on the tag size. For example, some computations predict that the likelihood of finding a defect is 94% when using a tag size of 4 bits.
[0040] To help with understanding, Table 1 lists a list of some memory coloring or tagging operations provided by the ARMv8.5 architecture. As shown in Table 1, the memory coloring or tagging operations include privileged operations, a command set for coloring memory, a command set for coloring addresses and pointers, and commands for performing arithmetic operations on pointers with tags. Functions such as managing tag arrays, interrupting execution on incorrect dereferencing operations, and controlling the coloring mechanism (such as turning coloring on or off) are managed by system registers and microcode.
[0041]
[0042]
[0043] The coloring instructions are primarily used to support the following basic program flow: reserving a memory granule, obtaining a color value for a memory pointer, and coloring or tagging the reserved memory using the same color value obtained for the memory pointer. This basic flow can be understood with reference to an example embodiment 100 shown in Figure 1 The example memory region 106 is shown as a frame on a memory stack 154. Alternatively, the memory region 106 can be allocated from a heap space or any suitable type of memory region configured as data space or read / write memory region. The memory region 106 can be associated with a color value 138 by a tag array 156. Each entry in the tag array, such as entry 120, associates a color value 138 with a memory region 106 by a memory pointer 118. The tag array 156 can include multiple entries 122 and 120, each having its own color value 138 and 124 and pointer 114 and 118. When the memory pointer used by the code module 126 includes the same color value 138 as the memory region 106 being accessed 128, the memory access is successful. An incorrect dereference is when a pointer access to memory is captured at runtime that uses a different color value than the memory being accessed, and causes a processing exception.
[0044] The call flow integrity within the apparatus 100 is enhanced by a feature referred to herein as branch target instruction protection. In an apparatus (100) that provides branch target instruction (BTI) protection, certain instructions are marked as branch targets. Whenever a program branch or jump operation passes control of execution to an instruction that is marked as a branch target, the program continues normal execution. When a program branch or jump operation passes control of execution to an instruction that is not properly marked as a branch target, a processing exception is raised. As used herein, the term “branch target instruction” refers to an instruction that has been marked as a branch target.
[0045] Branch target instruction protection can be implemented in a variety of ways. For example, the ARMv8. architecture manages a specially protected memory region 134 and provides BTI virtual assembly instructions. Within the protected memory region 134, branches or jumps to most instructions will raise a processing exception. However, under certain conditions, a jump or branch 132 within the protected memory region to a BTI instruction will not raise a branch target exception and will allow the subsequent instructions within the memory region 134 to continue to be executed. The apparatus 100 includes a protected memory region 134 in which the BTI mechanism is active such that only BTI instructions can be the target of a programmatic branch or jump. After a branch 132 to a BTI instruction, the subsequent instructions after the BTI instruction will be executed in order.
[0046] Alternatively, the BTI mechanism can be implemented in any desired manner, such as by placing markers or special instructions in the code, or by maintaining a table of allowed branch targets or entry points, or other suitable manner that forces only certain instructions to be the allowed targets of a branch. Those of ordinary skill in the art will readily recognize that any branch target protection mechanism that ensures that programmatic jump or branch operations can only be performed to certain well-defined instructions can be advantageously employed without departing from the spirit and scope of the present disclosure.
[0047] The execution flow can be enforced by placing a branch target instruction at the beginning of a routine or function, without marking any of the remaining instructions in the routine or function as a BTI. This guarantees that the routine or function must always be entered at the desired entry point or start instruction, and any attempt to enter the routine at some other location within the function body will result in a processing exception. Thus, the BTI protection prevents a malicious application from using or accessing portions of instructions or sequences of instructions in the routine or function for its own purposes.
[0048] Figure 2 A code overview 200 is shown that illustrates aspects of the disclosed embodiments providing mechanisms for providing near-full memory safety. Figure 2 The features shown in FIG. 1 are applicable to providing memory safety and call flow integrity within a computing device of an apparatus 100 as described above Figure 1 The features shown in FIG. 1 are applicable to providing memory safety and call flow integrity within a computing device of an apparatus 100 as described above
[0049] For illustrative purposes, memory regions and executable code having the same color value are represented by shading, with regions using the same shading pattern having similar color values. A first pattern 250 will represent a first color value such as red, a second pattern 252 represents a second other color value such as blue, and a third pattern 220 represents a third other color value such as gray.
[0050] The color values used in functions 202 and 208 and shading routines 204, 206, 210, and 212 are predetermined and set during code generation. This makes these color values hard-coded, i.e., loaded into the code segment at runtime, thereby protecting them from tampering during program execution.
[0051] Overview 200 depicts a software call flow scenario in which a first function 202, func1(), programmatically calls or branches to a second function 208, func2(). Also shown is a portion of a memory stack 214, where portions of memory, sometimes referred to as stack frames 216 and 218, are allocated for use by first function 202 and second function 208, respectively. Overview 200 illustrates the state of memory coloring, i.e., the allocation of color values, at a point in time when program execution occurs within a body portion 246 of second function 208.
[0052] In the illustrated embodiment 200 , when the first function 202 reaches a point 248 where a call or branch 226 is required to a second function 208 , the first function 202 passes control 222 or execution flow to the shading routine 204 . Figure 2 Arrows in FIG. 2 , such as arrows 222 and 224, depict the transfer of program execution flow between different software routines or functions. A routine, such as first function 202, transfers execution flow 222 to shading routine 204 by programmatically calling shading routine 204. When shading routine 204 has completed its processing, execution flow is returned 224 to the calling routine or function, as indicated by arrow 224.
[0053] As will be discussed further below, during program execution, memory shading is modified by shading routines that are used to protect shading operations from tampering or misuse. Each of the four shading routines 204, 206, 210, and 212 is similar, but differs in the color values they apply and the memory regions on which they operate. The four shading routines 204, 206, 210, and 212 are configured to perform the following steps, in the following order: identify the calling routine, verify that the calling routine is authorized to use the shading routine, apply the predetermined color to the desired memory region, and return to the calling function or routine.
[0054] The color values applied by shading routines 204, 206, 210, and 212 are predetermined and protected from modification by hardcoding them within the code space. However, an attacker can still control shading by modifying program flow, thereby executing shading instructions without first performing identification and authorization checks. To prevent the misuse of shading instructions, each shading routine 204, 206, 210, and 212 is protected using branch target instruction protection, as described above.
[0055] Each shading routine 204, 206, 210, and 212 includes a basic block that begins with a single branch target instruction, which means that branch target instruction protection is used to ensure that the shading routines 204, 206, 210, and 212 can only be entered at their beginning or predefined entry points, and all processing steps included in the shading routines 204, 206, 210, and 212 must be executed sequentially, thereby preventing unauthorized malicious applications from skipping the identification and authorization steps and executing shading instructions without authorization.
[0056] The term "decolorization" refers to associating a reserved or inaccessible color value 220 with a memory region, wherein the reserved color value 220 is not used to access any memory region, and when the inaccessible color value is associated with the memory region, the decolorized memory region cannot be accessed by any program code. As used herein, the term "inaccessible color value 220" is used to refer to a color value 220 of a memory region that is inaccessible to any program code, such as the reserved or inaccessible color value 220 shown in overview 200. The colorization routines 204 and 212 for coloring memory with the inaccessible color 220 may be referred to herein as decolorization routines.
[0057] When implemented in an ARMv8.5 type processor, branch target instruction protection is implemented by loading shading routines 204, 206, 210, and 212 into a protected memory area and placing a BTI virtual assembly instruction at the beginning of the routine. There is only one BTI instruction in each shading routine 204, 206, 210, and 212, located at the beginning of the routine, thereby preventing entry into the shading routine except through the BTI instruction at the beginning of the routine.
[0058] The above-described coloring routines 204, 206, 210, and 212 can be used to provide near-full memory security and reduce the risk of ROP attacks when a first function 202 calls a second function 208. Before branching 226 to the second function 208, the first function 202 calls the coloring routine 204 to decolorize a memory region 216 associated with the first function 202. The decoloring routine 204 is hardcoded with a predefined inaccessible color value 220 and is used to associate the memory region 216 with the inaccessible color value 220. Coloring the memory region 216 with the inaccessible color prevents any access or modification to the memory region 216 used by the first function 202 when control is passed to the second function 208.
[0059] After receiving control 226, the second function begins calling 234 a shading routine 210 for shading the memory using a color value 250, which makes the memory region 218 accessible to the second function 208. Upon completion, the shading routine 210 returns to the second function 208, where the second function can continue its intended processing 240 while interacting with the shaded memory region 218. Once the second function 208 completes its processing 240, and before returning to the first function 202, the second function 208 calls 238 a decolorization routine 212, which is hardcoded such that an inaccessible color value 220 is associated with the memory region 218, thereby making the memory region 218 inaccessible to any code module.
[0060] In some embodiments, such as when memory region 218 is already filled with highly sensitive data, additional security can be provided by resetting the memory values stored in memory region 218 to all zero values. This step completely erases the data, making it impossible to recover, even by a program that manages to bypass memory coloring protections.
[0061] After returning from the second function 208, the first function 202 prepares to resume execution by calling 230 the shading routine 206, wherein the shading routine 206 is used to recolor the memory region 216 using the predetermined first color value 252. The first function 202 can then resume its processing while accessing its allocated memory region 216.
[0062] Advantageously, the color values used, such as red 250, blue 252, and gray 220, representing an inaccessible color value, are all distinct and different from one another. Using a different color value for each memory color prevents the first function 202 from accessing the memory 218 belonging to the second function 208, and prevents the second function 208 from accessing the memory 216 belonging to the first function 202. The inaccessible color value 220 being different from the first color value 250 or the second color value 252 prevents the first function 202 or the second function 208 from accessing the decolored memory while the memory is protected (i.e., the memory is decolored or assigned the inaccessible color value 220).
[0063] The advantages of the above embodiments can be appreciated by considering the risk model, i.e., an attacker gains control of the colorings and thus can access memory regions containing sensitive data. Since the W^X protection is built into the device 100, hard-coding color values and incorporating color values into code space prevents an attacker from modifying the color values that are hard-coded in each coloring routine. The coloring routines 204, 206, 210, and 212 are protected with branch target instruction protection and the entry point or start instruction of each coloring routine 204, 206, 210, and 212 is marked with a BTI to prevent an attacker from bypassing the identification and authorization steps included in each coloring routine 204, 206, 210, and 212 and using the coloring operations as a tool for malicious purposes. Thus, combining two hardware primitives, memory coloring and branch target instruction protection, in a disclosed manner provides a simple and effective method of enhancing memory security and call flow integrity.
[0064] Since both the memory coloring and branch target instruction protection primitives are very lightweight, the only system computation overhead contemplated by the disclosed embodiments comes from the additional code instructions required to manipulate the color values and protect the coloring routines. Thus, the computation and memory usage overhead can be estimated to be about one to three percent (1-3%). In contrast, conventional solutions that provide memory safety and call flow integrity require about 400% computation and memory usage overhead.
[0065] The attack surface or risk associated with a particular embodiment is inversely proportional to the granularity or size of each memory region being colored. An attacker attacking a larger memory region requires access to more data. More small memory regions increase the complexity and overhead associated with applying different color values to many small memory regions. Thus, there is a tradeoff between risk and overhead.
[0066] A low risk embodiment can apply different color values using a more fine-grained approach after each basic block in the entry and exit code. Each basic block in a function uses a different memory color value rather than the entire function using the same memory color value. The term "basic block" as used herein refers to a straight-line code sequence, or sequence of software instructions, with no entry branches other than the entry and no exit branches other than the exit. Each basic block using a different color value prevents an attacker that compromises one basic block or color value from accessing data associated with other basic blocks in the same function.
[0067] In embodiments where the size of the objects is large, it can be advantageous for the memory region used to store each storage object to use a different color value, i.e., each storage object is associated with its own color value. As used herein, the term "storage object" refers to an instance of a data structure or class stored in computer memory.
[0068] In certain embodiments, the parameter or value passed to the called function from the calling function can be placed on the stack by the calling function, wherein, this parameter or value can be accessed by the called function. As used herein, the term "stack parameter" refers to the parameter or storage object that is placed on the stack when starting to transfer between the calling function and the called function. It may be advantageous to apply a color value different from the color value used by the calling function or the called function to these stack parameters. By using different color values for the stack parameters, it is possible to manage the access of the stack parameters independently of other memory areas that the calling function or the called function use.
[0069] A more coarse-grained shading method similar to the above Figure 2 An embodiment of coloring by function is shown. For example, a first color value (e.g., blue 252) is used during execution of a first function 202, and a second color value (e.g., red 250) is used during execution of a second function 208. In embodiment 200, the entire stack frame 218 associated with the second function, as well as any other memory areas allocated by the second function, receives the same color value 250.
[0070] A common software development practice is for one company to develop an application that utilizes another company's library. Application developers often have less understanding and trust in third-party libraries than they do in their own application code. The source code for the library may not be available, or the cost of modifying and verifying the library may be prohibitive, so modifying the library to use a function-by-function approach to memory coloring, as described above, may not be advisable. However, the aforementioned approach of using memory coloring and branch target instruction protection can still be applied to improve overall system security without modifying the library itself. By using a first color value for the code in the application and a second color value for all functions and routines in the library, memory security and call flow integrity can be improved. Although this approach is coarser or less granular than the other approaches described in this article, it still offers significant advantages while keeping development and implementation costs low.
[0071] Figure 3 A flowchart of an exemplary method 300 for providing memory protection and call flow integrity in a computing device according to various aspects of the disclosed embodiments is shown. The method 300 is applicable to a wide range of modern computing devices, such as the aforementioned reference Figure 1 The computing device 100 is described. The method 300 utilizes a computing device that provides two hardware primitives, memory coloring and branch target instruction protection, which are common in many modern mobile communication devices, such as cell phones, mobile phones, tablet computers, and many wireless network computing devices.
[0072] The method begins when a first function 320 prepares to branch to a second function 322. Prior to branching to the second function 322, memory used by the first function 320 and memory pointers embedded in the code of the first function 320 are colored using a first color value, thereby enabling the first function 320 to complete its intended processing. When preparing to branch, the memory associated with the first function 320 is decolorized 302 by associating the memory region with an inaccessible color value, rendering the memory inaccessible from any code segment. As will be discussed further below, the decolorization and decolorization are accomplished by branching to a specially configured decolorization routine.
[0073] The first function 320 then branches 304 to the second function 322. Before initiating processing within the second function 322, the memory region and associated memory pointer are colored using a second color value 306. The memory region can be any desired type of computer-accessible memory, such as a stack frame, heap space, or other target memory region. Once colored using the second color, the second function 322 can access the associated memory region to perform any desired processing and software operations 308.
[0074] Before returning to the first function 320, the second function 322 decolorizes its associated memory region by marking it with an inaccessible color value or associating it with an inaccessible color value 310 to protect the memory region from unauthorized access. Control is returned to the first function 320, where, before continuing any processing, the memory associated with the first function is colored using the first color value 314, allowing the first function 320 to access the associated memory region. The first function 320 can then continue its processing 316.
[0075] Figure 4 A flowchart of an exemplary shading routine 400 incorporating aspects of the disclosed embodiments is shown. The shading routine 400 is suitable for performing the above-mentioned reference Figure 3 The exemplary method 300 described includes a coloring or decoloring step.
[0076] The shading routine 400 is advantageously protected by branch target instruction protection and WX or data execution prevention mechanisms. The entry point or start instruction 450 of the shading routine 400 is marked as a branch target by any appropriate BTI method as described above. Upon entry, the processor or other BTI mechanism verifies 402 that the instruction branched to is a valid branch target. If a branch is attempted to any instruction within the shading routine 400 other than the predefined and appropriately marked entry point 450, a handling exception is generated and appropriate exception handling can be initiated.
[0077] Next, the shading routine identifies 404 the calling routine. This identification can be accomplished by any desired means, such as checking a return address or other means. A check is then performed 406 to ensure that the calling routine or function is authorized to use the shading routine 400. If the calling routine or function is not authorized (406-N), the shading routine is exited 408 without performing any shading operations. Before returning to the calling function, in some embodiments, it may be necessary to perform error handling, return an error code, or otherwise indicate that an exception has occurred so that appropriate action can be taken.
[0078] When it is determined that the calling routine is authorized (406-Y), the memory region is colored 410 using a hardcoded memory color. Using hardcoded color values improves security by preventing attackers from exploiting colored instructions during an attack. Coloring the memory allows the calling routine to access the memory while completing the required processing. Control is then returned 412 to the calling routine.
[0079] For security reasons, it is very important to protect the hard-coded color values from being modified. As described above, the hard-coded color values are set during code generation and stored in the code space along with the program instructions. At runtime, the shading routine 400 is loaded into the execute-only code area where it can be protected using a data execution prevention mechanism.
[0080] Thus, while the basic novel features of the invention as applied to exemplary embodiments of the invention have been shown, described, and pointed out herein, it will be understood that various omissions, substitutions, and changes may be made to the form and details of the apparatus and methods shown, as well as to the operation of the apparatus, by those skilled in the art, without departing from the spirit and scope of the invention. Further, it is expressly intended that all combinations of elements which perform substantially the same function in substantially the same manner to achieve the same results are within the scope of the invention. Furthermore, it will be appreciated that the structures and / or elements shown and / or described in conjunction with any form or embodiment of the invention disclosed may be incorporated into any other form or embodiment disclosed, described, or suggested as a general matter of design choice. The invention is therefore limited only by the scope of the appended claims.
Claims
1. An apparatus (100) comprising a processor (150) coupled to a memory (152), wherein: The processor (150) and the memory (152) are configured to provide branch target instruction protection and memory coloring protection, and the processor (150) is configured to call a second function (208) from a first function (202) in the following manner: coloring a first memory region (216) associated with the first function (202) using an inaccessible color value (220); Branch to the second function (208); coloring a second memory region (218) associated with the second function (208) using a second color value (250); performing an operation on the second memory area (218); coloring the second memory region (218) using the inaccessible color value (220); Return to the first function (202); The first memory region (216) is colored using a first color value (252), wherein The first color value (252), the second color value (250), and the inaccessible color value (220) each comprise a different color value; The coloring includes: branching to a shading routine (204, 206, 210, and 212), wherein the shading routine includes a basic block that begins with a single branch target instruction; Identify and authorize calling routines; Coloring the memory region associated with the calling routine using a hard-coded color value; Return to the calling routine.
2. The device (100) according to claim 1, characterized in that The shading routines (204, 206, 210, and 212) are located in an execute-only memory region, and the processor (150) is configured to prevent writes to the execute-only memory region.
3. The device (100) according to claim 1, characterized in that The first memory region (216) and the second memory region (218) are allocated in a read / write portion of the memory (152) and include at least one of a stack frame and a heap region, and the processor (150) is configured to prevent execution of data in the first memory region or the second memory region.
4. The device (100) according to claim 1, characterized in that One or more stack parameters are passed from the first function (202) to the second function (208), the one or more stack parameters being colored using a third color value, the third color value being different from any one of the inaccessible color value and the first color value, the processor (150) being configured to read and / or write the one or more stack parameters.
5. The device (100) according to claim 1, characterized in that One or more memory objects are stored in the second stack frame (218), each of the one or more memory objects is colored with a different color value, and the processor (150) is used to read and / or write the one or more memory objects.
6. The device (100) according to claim 1, characterized in that The second function (208) includes a plurality of basic blocks, and a storage object associated with each basic block is colored using a different color value.
7. The device (100) according to claim 1, characterized in that Program instructions associated with an application are colored using a fourth color value, all routines associated with a software library accessed by the application are colored using a fifth color value, wherein the fourth color value is different from the fifth color value, and the processor (150) is used to execute the application.
8. The device (100) according to claim 1, characterized in that The second memory region (218) includes a stack frame, and coloring the second memory region (218) using the inaccessible color value (220) includes the processor (150) resetting the second memory region (218) to a zero value.
9. The device (100) according to any one of claims 1 to 8, characterized in that The apparatus comprises a mobile communication device.
10. A computer-implemented method (300 and 400), wherein: The computer is used to provide branch target instruction protection and memory coloring protection, and the method includes: Coloring a first memory region associated with a first function using an inaccessible color value (302); Branch (304) to the second function; coloring a second memory region associated with the second function using a second color value (306); performing an operation on the second memory region based on the second function (308); Coloring the second memory area using the inaccessible color value (310); Return (312) to the first function; The first memory region is colored using a first color value (314), wherein The first color value, the second color value, and the inaccessible color value each comprise a different color value; The coloring (302, 306, 310 and 314) includes: branching to a shading routine, wherein the shading routine comprises a single basic block beginning with a branch target instruction; Identify and authorize the calling routine (404 and 406); Coloring a memory region associated with the calling routine using a hard-coded color value (410); Return (414) to the calling routine.
11. The method (300 and 400) according to claim 10, characterized in that The shading routines are located in the execute-only memory area.
12. The method (300 and 400) according to claim 10, characterized in that One or more stack parameters are passed from the first function to the second function, wherein the one or more stack parameters are colored using a third color value that is different from any of the inaccessible color value, the first color value, and the second color value.
13. The method (300 and 400) according to claim 10, characterized in that One or more memory objects are stored in the second stack frame, each of the one or more memory objects is colored using a different color value.
14. The method (300 and 400) according to any one of claims 10 to 13, characterized in that The second function includes a plurality of basic blocks, and a storage object associated with each basic block is colored using a different color value.
15. A computer program product comprising non-transitory computer program instructions which, when executed by a processor (150), cause the processor (150) to perform the method of any one of claims 10 to 14.
Citation Information
Patent Citations
Buffer management method and device
CN103455443A
Protecting Caller Function from Undesired Access by Callee Function
US20080282358A1