[SW Security] CRCount: Pointer Invalidation with Reference Counting to Mitigate Use-after-free in Legacy C/C++, Network and Distributed System Security Symposium (NDSS), Feb. 2019

CRCount: Pointer Invalidation with Reference Counting to Mitigate Use-after-free in Legacy C/C++, Network and Distributed System Security Symposium (NDSS) 2019


Jangseop Shin, Donghyun Kwon, Jiwon Seo, Yeongpil Cho, Yunheung Paek


본 논문은 C/C++ 프로그램에 대한 공격으로 많이 사용되는 Use-after-free 취약점에 대한 방어 기법을 제안한다. 이를 위해 컴파일 단계에서 코드를 수정하여 Heap object에 대한 Reference Counting을 수행하여 이를 통해 Heap object의 해제를 dangling pointer가 없어질 때까지 지연시킨다. 또한 실험을 통해 이 approach의 효율성을 보여주었다.

0
0

International Papers

Software Optimization and Reconstruction Modulo Scheduler Implementation for VLIW Processor, International SoC Design Conference (ISOCC) Nov 2014
Software Optimization and Reconstruction Improving Data Transfer Throughput in Embedded Memory Subsystems , The 3rd International Workshop on Ubiquitous Computing & Applications (IWUCA 2012), also recommended as one of the best papers, Dec 2012
Software Optimization and Reconstruction An Efficient Management Technique for Fast SRAM Subsystems , International Conference on Convergence and Hybrid Information Technology (ICHIT 2012), Aug 2012
Software Optimization and Reconstruction Fast graph-based instruction selection for multi-output instructions, Software-Practice & Experience, Dec 2010
Software Optimization and Reconstruction Compiler triggered C level error check, The Eighth Asian Symposium on Programming Languages and Systems(APLAS), Nov 2010
Software Optimization and Reconstruction Methodology for the efficient use of operands in the design of compound instructions in ASIP, International SoC Design Conference (ISOCC), Nov 2009
Software Optimization and Reconstruction Iterative Algorithm for Compound Instruction Selection with Register Coalescing, 12th Euromicro conference on Digital System Design (DSD), Aug. 2009
Software Optimization and Reconstruction Adaptive Scratch Pad Memory Management for Dynamic Behavior of Multimedia Applications, IEEE Transactions on Transactions on Computer Aided Design of Integrated Circuits and Systems (TCAD), Mar 2009
Software Optimization and Reconstruction SoarGen : A retargetable compiler based on Architecture Description Language and its application on a fixed point audio codec, Asia and South Pacific Design Automation Conference (ASP-DAC), Jan 2009
Software Optimization and Reconstruction Management Environment of Mass Windows Servers for Server-based Computing, The International Conference On Information Networking, Jan 2009
Software Optimization and Reconstruction Management Environment of Mass Windows Servers for Server-based Computing, The International Conference On Information Networking, Jan 2009
Software Optimization and Reconstruction Register Coalescing Techniques for Heterogeneous Register Architectures, ACM Transactions on Embedded Computing Systems (TECS), Jan 2009
Software Optimization and Reconstruction A Retargetable Parallel-Programming Framework for MPSoC, ACM Transactions on Design Automation of Electronic Systems, Jul 2008
Software Optimization and Reconstruction Compiler driven data layout optimization for regular/irregular array access patterns, ACM SIGPLAN Conference on Languages, Compilers, and Tools for Embedded Systems (LCTES), and also appears in ACM SIGPLAN Notices, Jun 2008
Software Optimization and Reconstruction An OpenMP Translator with Retargetable Parallel Programming Model for MPSoC, International Conference on Ubiquitous Information Technologies & Applications (ICUT), Dec 2007
Software Optimization and Reconstruction A code-generator generator for multi-output instructions, The International Conference on Hardware-Software Codesign and System Synthesis(CODES+ISSS), Oct 2007
Software Optimization and Reconstruction Software Controlled Memory Layout Reorganization for Irregular Array Access Patterns, ACM International Conference on Compilers, Architecture, and Synthesis for Embedded Systems (CASES 2007), Oct 2007
Software Optimization and Reconstruction Optimistic Coalescing for Heterogeneous Register Architectures, ACM Conference on Languages, Compilers and Tools for Embedded Systems or ACM SIGPLAN Notice, Jun 2007 ( Best paper)
Software Optimization and Reconstruction Preprocessing Strategy for Effective Modulo Scheduling on Multi-Issue Digital Signal Processors, International Conference on Compiler Construction (CC), also appear in Lecture Notes in Computer Science, Mar 2007
Software Optimization and Reconstruction A code generation strategy for heterogeneous register architectures, Workshop on Interaction between Compiler and Architecture (Interact), Feb 2007