Papers
Topics
Authors
Recent
Search
2000 character limit reached

DeTRAP: RISC-V Return Address Protection With Debug Triggers

Published 30 Aug 2024 in cs.CR | (2408.17248v1)

Abstract: Modern microcontroller software is often written in C/C++ and suffers from control-flow hijacking vulnerabilities. Previous mitigations suffer from high performance and memory overheads and require either the presence of memory protection hardware or sophisticated program analysis in the compiler. This paper presents DeTRAP (Debug Trigger Return Address Protection). DeTRAP utilizes a full implementation of the RISC-V debug hardware specification to provide a write-protected shadow stack for return addresses. Unlike previous work, DeTRAP requires no memory protection hardware and only minor changes to the compiler toolchain. We tested DeTRAP on an FPGA running a 32-bit RISC-V microcontroller core and found average execution time overheads to be between 0.5% and 1.9% on evaluated benchmark suites with code size overheads averaging 7.9% or less.

Definition Search Book Streamline Icon: https://streamlinehq.com
References (62)
  1. M. Abadi, M. Budiu, U. Erlingsson, and J. Ligatti, “Control-flow integrity principles, implementations, and applications,” ACM Transactions on Information Systems Security, vol. 13, pp. 4:1–4:40, November 2009.
  2. J. Afek and A. Sharabani, “Dangling Pointer: Smashing the Pointer for Fun and Profit,” in Black Hat USA, 2007.
  3. T. Ajayi, V. A. Chhabria, M. Fogaça, S. Hashemi, A. Hosny, A. B. Kahng, M. Kim, J. Lee, U. Mallappa, M. Neseem, G. Pradipta, S. Reda, M. Saligane, S. S. Sapatnekar, C. Sechen, M. Shalan, W. Swartz, L. Wang, Z. Wang, M. Woo, and B. Xu, “Toward an open-source digital flow: First learnings from the openroad project,” in Proceedings of the 56th Annual Design Automation Conference 2019, ser. DAC ’19.   New York, NY, USA: Association for Computing Machinery, 2019.
  4. N. S. Almakhdhub, A. A. Clements, S. Bagchi, and M. Payer, “µRAI: Securing Embedded Systems with Return Address Integrity,” in Proceedings of the Network and Distributed System Security (NDSS) Symposium, San Diego, CA, USA, February 2020.
  5. A. Amid, D. Biancolin, A. Gonzalez, D. Grubb, S. Karandikar, H. Liew, A. Magyar, H. Mao, A. Ou, N. Pemberton, P. Rigge, C. Schmidt, J. Wright, J. Zhao, Y. S. Shao, K. Asanović, and B. Nikolić, “Chipyard: Integrated design, simulation, and implementation framework for custom socs,” IEEE Micro, vol. 40, no. 4, pp. 10–21, 2020.
  6. K. Asanović, R. Avizienis, J. Bachrach, S. Beamer, D. Biancolin, C. Celio, H. Cook, D. Dabbelt, J. Hauser, A. Izraelevitz, S. Karandikar, B. Keller, D. Kim, J. Koenig, Y. Lee, E. Love, M. Maas, A. Magyar, H. Mao, M. Moreto, A. Ou, D. A. Patterson, B. Richards, C. Schmidt, S. Twigg, H. Vo, and A. Waterman, “The rocket chip generator,” EECS Department, University of California, Berkeley, Tech. Rep. UCB/EECS-2016-17, Apr 2016. [Online]. Available: http://www2.eecs.berkeley.edu/Pubs/TechRpts/2016/EECS-2016-17.html
  7. “BEEBS git repository.” [Online]. Available: https://github.com/mageec/beebs
  8. T. Bletsch, X. Jiang, V. W. Freeh, and Z. Liang, “Jump-oriented Programming: A New Class of Code-reuse Attack,” in Proceedings of the 6th ACM Asia Conference on Computer & Communications Security (ASIACCS), Hong Kong, China, 2011, pp. 30–40.
  9. N. Burow, X. Zhang, and M. Payer, “Sok: Shining light on shadow stacks,” in 2019 IEEE Symposium on Security and Privacy (SP), 2019, pp. 985–999.
  10. N. Carlini and D. Wagner, “ROP is still dangerous: Breaking modern defenses,” in 23rd USENIX Security Symposium (USENIX Security 14).   San Diego, CA: USENIX Association, Aug. 2014, pp. 385–399.
  11. S. Chen, J. Xu, E. C. Sezer, P. Gauriar, and R. K. Iyer, “Non-control-data Attacks Are Realistic Threats,” in Proceedings of the 14th USENIX Security Symposium (SEC), Baltimore, MD, 2005, pp. 12–12.
  12. K. Cheng, Relax gp could be platform specific register…. [Online]. Available: https://github.com/riscv-non-isa/riscv-elf-psabi-doc/pull/371
  13. T.-C. Chiueh and F.-H. Hsu, “RAD: a compile-time solution to buffer overflow attacks,” in Proceedings 21st International Conference on Distributed Computing Systems, 2001, pp. 409–417.
  14. Clang 13.0 Documentation, Control Flow Integrity. [Online]. Available: https://releases.llvm.org/13.0.1/tools/clang/docs/ControlFlowIntegrity.html
  15. Clang 13.0 Documentation, ShadowCallStack. [Online]. Available: https://releases.llvm.org/13.0.1/tools/clang/docs/ShadowCallStack.html
  16. T. Cloosters, D. Paaßen, J. Wang, O. Draissi, P. Jauernig, E. Stapf, L. Davi, and A.-R. Sadeghi, “RiscyROP: automated return-oriented programming attacks on risc-v and arm64,” in Proceedings of the 25th International Symposium on Research in Attacks, Intrusions and Defenses, ser. RAID ’22.   New York, NY, USA: Association for Computing Machinery, 2022, p. 30–42.
  17. M. Conti, S. Crane, L. Davi, M. Franz, P. Larsen, M. Negro, C. Liebchen, M. Qunaibit, and A.-R. Sadeghi, “Losing control: On the effectiveness of control-flow integrity under stack attacks,” in Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, ser. CCS ’15.   Denver, CO: ACM, 2015, pp. 952–963.
  18. S. Crane, C. Liebchen, A. Homescu, L. Davi, P. Larsen, A.-R. Sadeghi, S. Brunthaler, and M. Franz, “Readactor: Practical code randomization resilient to memory disclosure,” in 2015 IEEE Symposium on Security and Privacy, 2015, pp. 763–780.
  19. J. Criswell, N. Dautenhahn, and V. Adve, “KCoFI: Complete Control-Flow Integrity for Commodity Operating System Kernels,” in Proceedings of the 35th IEEE Symposium on Security and Privacy (S&P), San Jose, CA, May 2014, pp. 292–307.
  20. N. Dautenhahn, T. Kasampalis, W. Dietz, J. Criswell, and V. Adve, “Nested Kernel: An Operating System Architecture for Intra-Kernel Privilege Separation,” in Proceedings of the 20th International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS), Istanbul, Turkey, 2015, pp. 191–206.
  21. L. Davi, A.-R. Sadeghi, D. Lehmann, and F. Monrose, “Stitching the gadgets: On the ineffectiveness of coarse-grained control-flow integrity protection,” in 23rd USENIX Security Symposium (USENIX Security 14).   San Diego, CA: USENIX Association, Aug. 2014, pp. 401–416.
  22. L. Delshadtehrani, S. Canakci, B. Zhou, S. Eldridge, A. Joshi, and M. Egele, “PHMon: A programmable hardware monitor and its security use cases,” in 29th USENIX Security Symposium (USENIX Security 20).   USENIX Association, August 2020, pp. 807–824.
  23. Digilent, Arty A7 Reference Manual. [Online]. Available: https://digilent.com/reference/programmable-logic/arty-a7/reference-manual
  24. Y. Du, Z. Shen, K. Dharsee, J. Zhou, R. J. Walls, and J. Criswell, “Holistic Control-Flow Protection on Real-Time Embedded Systems with Kage,” in 31st USENIX Security Symposium (USENIX Security 22).   Boston, MA: USENIX Association, Aug. 2022, pp. 2281–2298.
  25. R. T. Edwards, “Google/skywater and the promise of the open pdk,” in Workshop on Open-Source EDA Technology, 2020.
  26. “CoreMark: An EEMBC benchmark.” [Online]. Available: https://www.eembc.org/coremark
  27. “CoreMark-Pro: An EEMBC benchmark.” [Online]. Available: https://www.eembc.org/coremark-pro
  28. E. Göktas, E. Athanasopoulos, H. Bos, and G. Portokalidis, “Out of Control: Overcoming Control-Flow Integrity,” in Proceedings of the 35th IEEE Symposium on Security and Privacy (S&P), San Jose, CA, May 2014, pp. 575–589.
  29. S. Gravani, M. Hedayati, J. Criswell, and M. L. Scott, “Fast intra-kernel isolation and security with iskios,” in 24th International Symposium on Research in Attacks, Intrusions and Defenses, 2021, pp. 119–134.
  30. Y. Guo, L. Chen, and G. Shi, “Function-oriented programming: A new class of code reuse attack in c applications,” in 2018 IEEE Conference on Communications and Network Security (CNS), 2018, pp. 1–9.
  31. M. Hedayati, S. Gravani, E. Johnson, J. Criswell, M. L. Scott, K. Shen, and M. Marty, “Hodor: Intra-Process Isolation for High-Throughput Data Plane Libraries,” in 2019 USENIX Annual Technical Conference (USENIX ATC 19).   Renton, WA: USENIX Association, Jul. 2019, pp. 489–504.
  32. Intel Corp., “Intel 64 and IA-32 Architectures Software Developer’s Manual,” April 2021, 325384-074US.
  33. G.-A. Jaloyan, K. Markantonakis, R. N. Akram, D. Robin, K. Mayes, and D. Naccache, “Return-oriented programming on risc-v,” in Proceedings of the 15th ACM Asia Conference on Computer and Communications Security, ser. ASIA CCS ’20.   New York, NY, USA: Association for Computing Machinery, 2020, p. 471–480.
  34. J. Jang and B. B. Kang, “In-process memory isolation using hardware watchpoint,” in Proceedings of the 56th Annual Design Automation Conference 2019, ser. DAC ’19.   New York, NY, USA: Association for Computing Machinery, 2019.
  35. J. Jang and B. B. Kang, “Revisiting the ARM Debug Facility for OS Kernel Security,” in Proceedings of the 56th Annual Design Automation Conference 2019, ser. DAC ’19.   New York, NY, USA: Association for Computing Machinery, 2019.
  36. P. Kirth, D146463: [CodeGen][RISCV] Change Shadow Call Stack Register to X3. [Online]. Available: https://reviews.llvm.org/D146463
  37. D. Kwon, J. Shin, G. Kim, B. Lee, Y. Cho, and Y. Paek, “uXOM: Efficient eXecute-Only Memory on ARM Cortex-M,” in Proceedings of the 28th USENIX Security Symposium, ser. Security ’19.   Santa Clara, CA: USENIX Association, August 2019, pp. 231–247.
  38. C. Lattner and V. Adve, “LLVM: A compilation framework for lifelong program analysis & transformation,” in Proceedings of the 2nd International Symposium on Code Generation and Optimization, ser. CGO ’04.   Palo Alto, CA: IEEE Computer Society, 2004.
  39. C. Lattner, A. D. Lenharth, and V. S. Adve, “Making context-sensitive points-to analysis with heap cloning practical for the real world,” in ACM SIGPLAN Conference on Programming Language Design and Implementation, San Diego, CA, USA, June 2007, pp. 278–289.
  40. C. Liebchen, “Clang control flow integrity (cfi) bypass techniques.” [Online]. Available: https://github.com/0xcl/clang-cfi-bypass-techniques
  41. C. Liebchen, “Advancing memory-corruption attacks and defenses,” PhD thesis, Technische Universität Darmstadt, February 2018. [Online]. Available: https://tuprints.ulb.tu-darmstadt.de/8090/
  42. H. Liew, D. Grubb, J. Wright, C. Schmidt, N. Krzysztofowicz, A. Izraelevitz, E. Wang, K. Asanović, J. Bachrach, and B. Nikolić, “Hammer: a modular and reusable physical design flow tool: invited,” in Proceedings of the 59th ACM/IEEE Design Automation Conference, ser. DAC ’22.   New York, NY, USA: Association for Computing Machinery, 2022, p. 1335–1338.
  43. lowRISC contributors, “OpenTitan Security Model Specification.” [Online]. Available: https://docs.opentitan.org/doc/security/specs/secure_boot/
  44. V. Mohan, P. Larsen, S. Brunthaler, K. W. Hamlen, and M. Franz, “Opaque control-flow integrity,” in NDSS, 2015.
  45. B. H. Møller, J. G. Søndergaard, K. S. Jensen, M. W. Pedersen, T. W. Bøgedal, A. Christensen, D. B. Poulsen, K. G. Larsen, R. R. Hansen, T. R. Jensen et al., “Preliminary security analysis, formalisation, and verification of opentitan secure boot code,” in Nordic Conference on Secure IT Systems.   Springer, 2021, pp. 192–211.
  46. T. Mytkowicz, A. Diwan, M. Hauswirth, and P. F. Sweeney, “Producing wrong data without doing anything obviously wrong!” in Proceedings of the 14th International Conference on Architectural Support for Programming Languages and Operating Systems, ser. ASPLOS XIV.   New York, NY, USA: Association for Computing Machinery, 2009, p. 265–276.
  47. “Risc-v port of newlib.” [Online]. Available: https://github.com/riscv-collab/riscv-newlib
  48. J. Pallister, S. Hollis, and J. Bennett, “BEEBS: Open benchmarks for energy measurements on embedded platforms,” arXiv preprint arXiv:1308.5174, August 2013.
  49. D. Patterson, J. Bennett, P. Dabbelt, C. Garlati, G. S. Madhusudan, and T. Mudge, “Embench™: An evolving benchmark suite for embedded iot computers from an academic-industrial cooperative: Towards the long overdue and deserved demise of dhrystone,” in RISC-V Workshop Zurich, 2019.
  50. D. R. Piegdon and L. Pimenidis, “Hacking in physically addressable memory,” in Seminar of Advanced Exploitation Techniques, WS 2006/2007, vol. 12, 2007.
  51. R. Roemer, E. Buchanan, H. Shacham, and S. Savage, “Return-Oriented Programming: Systems, Languages, and Applications,” ACM Transactions on Information Systems Security (TISSEC), vol. 15, no. 1, pp. 2:1–2:34, Mar. 2012.
  52. A. Sadeghi, S. Niksefat, and M. Rostamipour, “Pure-call oriented programming (PCOP): chaining the gadgets using call instructions,” Journal of Computer Virology and Hacking Techniques, vol. 14, no. 2, pp. 139–156, 2018.
  53. D. Sehr, R. Muth, C. Biffle, V. Khimenko, E. Pasko, K. Schimpf, B. Yee, and B. Chen, “Adapting software fault isolation to contemporary CPU architectures,” in Proceedings of the 19th USENIX Security Symposium, ser. Security’10.   Washington, DC: USENIX Association, 2010, pp. 1–11.
  54. Z. Shen, K. Dharsee, and J. Criswell, “Fast execute-only memory for embedded systems,” in Proceedings of the 2020 IEEE Secure Development Conference, ser. SecDev ’20.   Atlanta, GA: IEEE Computer Society, 2020, pp. 7–14.
  55. R. Song, D74791 Add a –shuffle-sections=seed option to lld. [Online]. Available: https://reviews.llvm.org/D74791
  56. C. Tice, T. Roeder, P. Collingbourne, S. Checkoway, U. Erlingsson, L. Lozano, and G. Pike, “Enforcing Forward-edge Control-flow Integrity in GCC & LLVM,” in Proceedings of the 23rd USENIX Conference on Security Symposium, ser. SEC’14, 2014, pp. 941–955.
  57. M. Tran, M. Etheridge, T. Bletsch, X. Jiang, V. Freeh, and P. Ning, “On the Expressiveness of Return-into-libc Attacks,” in Proceedings of the 14th International Conference on Recent Advances in Intrusion Detection (RAID), Menlo Park, CA, 2011, pp. 121–141.
  58. R. J. Walls, N. F. Brown, T. Le Baron, C. A. Shue, H. Okhravi, and B. Ward, “Control-flow integrity for real-time embedded systems,” in 31st Conference on Real-Time Systems (ECRTS’19), July 2019.
  59. Y. Wang, J. Wu, T. Yue, Z. Ning, and F. Zhang, “RetTag: hardware-assisted return address integrity on risc-v,” in Proceedings of the 15th European Workshop on Systems Security, ser. EuroSec ’22.   New York, NY, USA: Association for Computing Machinery, 2022, p. 50–56.
  60. Z. Wang and X. Jiang, “HyperSafe: A Lightweight Approach to Provide Lifetime Hypervisor Control-Flow Integrity,” in Proceedings of the 31st IEEE Symposium on Security and Privacy (S&P), May 2010, pp. 380–395.
  61. J. Woodruff, R. N. Watson, D. Chisnall, S. W. Moore, J. Anderson, B. Davis, B. Laurie, P. G. Neumann, R. Norton, and M. Roe, “The CHERI Capability Model: Revisiting RISC in an Age of Risk,” in Proceeding of the 41st Annual International Symposium on Computer Architecture, ser. ISCA ’14.   Piscataway, NJ, USA: IEEE Press, 2014, pp. 457–468.
  62. J. Zhou, Y. Du, Z. Shen, L. Ma, J. Criswell, and R. J. Walls, “Silhouette: Efficient protected shadow stacks for embedded systems,” in 29th USENIX Security Symposium (USENIX Security 20).   USENIX Association, Aug. 2020, pp. 1219–1236.

Summary

No one has generated a summary of this paper yet.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Continue Learning

We haven't generated follow-up questions for this paper yet.

Tweets

Sign up for free to view the 1 tweet with 0 likes about this paper.