상세 보기
초록
Memory corruption vulnerabilities, such as out-of-bound memory access, are widely exploited by attackers to compromise system security. Numerous software-based techniques have been developed to prevent such vulnerabilities, but they often require a trade-off between security and performance. In response, Memory Tagging Extension (MTE) is one hardware-based technology that has been introduced to improve memory safety on the ARM architecture efficiently. However, ARM MTE suffers from low entropy and side-channel attacks. Consequently, additional techniques are urgent to enhance protection against pointer misuse arising from memory corruption. In this paper, we present Folded-Tag, a technique designed to efficiently safeguard pointers against unauthorized out-of-bounds access. Our method addresses the issue of low entropy 4-bit tag in ARM MTE, which makes the system vulnerable, by introducing folding and unfolding mechanisms for pointers. These mechanisms mitigate both speculative execution attacks and pointer guessing attacks. We implemented Folded-Tag in the LLVM compiler framework without requiring kernel modifications, making it suitable for deployment in systems supporting ARM MTE and Pointer Authentication (PA). To assess its effectiveness, we evaluated Folded-Tag on SPEC CPU2017 and NBench-byte benchmarks on an ARM-based Apple Silicon platform. We also applied Folded-Tag to real-world applications, including the NginX web server and ProFTPD FTP server, to demonstrate its compatibility and efficiency. Our experimental results show that Folded-Tag effectively mitigates attacks against existing hardware-assisted security features with a geometric mean performance overhead of less than 1%.
키워드
- 제목
- Folded-tag: Enhancing memory safety with efficient hardware-supported memory tagging
- 저자
- Yang, Sumin; Jin, Hongjoo; Choi, Wonsuk; Lee, Dong Hoon
- 발행일
- 2026-04
- 유형
- Article
- 권
- 163