{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,24]],"date-time":"2025-08-24T00:01:17Z","timestamp":1755993677558,"version":"3.44.0"},"reference-count":70,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2023,12,7]],"date-time":"2023-12-07T00:00:00Z","timestamp":1701907200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"EPSRC\/Innovate","award":["UK grant EP\/X015610\/1"],"award-info":[{"award-number":["UK grant EP\/X015610\/1"]}]},{"DOI":"10.13039\/501100006374","name":"Microsoft Research","doi-asserted-by":"publisher","award":["Fellowship Program 2021"],"award-info":[{"award-number":["Fellowship Program 2021"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]},{"name":"New Research","award":["Fellowship Program 2021"],"award-info":[{"award-number":["Fellowship Program 2021"]}]},{"name":"ANR","award":["ANR-18-CE25-0016"],"award-info":[{"award-number":["ANR-18-CE25-0016"]}]},{"name":"UK?s","award":["EPSRC EP\/V012134\/1"],"award-info":[{"award-number":["EPSRC EP\/V012134\/1"]}]},{"DOI":"10.13039\/501100006374","name":"Google","doi-asserted-by":"publisher","award":["Scholarship for Women in Computer Science 2022"],"award-info":[{"award-number":["Scholarship for Women in Computer Science 2022"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Proc. ACM Meas. Anal. Comput. Syst."],"published-print":{"date-parts":[[2023,12,7]]},"abstract":"<jats:p>Write buffer overflow is a widespread and prevalent memory safety violation in C\/C++, reported as the top vulnerability in 2022 and 2023. Secure memory allocators are generally used to protect systems against attacks that may exploit buffer overflows. Existing allocators mainly rely on two types of countermeasures to prevent or detect write overflows: canaries and guard pages, each with pros and cons in terms of detection latency and memory footprint.<\/jats:p>\n          <jats:p>For virtualized cloud applications, this paper follows the Out of Hypervisor (OoH) trend and introduces GuaNary, a safety guard against write overflows, allowing synchronous detection at a low memory footprint cost. OoH is a new virtualization research axis introduced in 2022 advocating the exposure of hardware features for virtualization to the guest OS so that its processes can take advantage of them. Based on the OoH principle, GuaNary leverages Intel Sub-Page write Permission (SPP), a recent hardware virtualization feature that allows to write-protect guest memory at the granularity of 128B (namely, sub-page) instead of 4KB. We implement a software stack, LeanGuard, which promotes the utilization of SPP from inside virtual machines by new secure allocators that use GuaNary. Our evaluation shows that for the same number of protected buffers, LeanGuard consumes 8.3\u00d7 less memory than SlimGuard, a recent state-of-art secure allocator. Further, for the same memory consumption, LeanGuard allows protecting 25\u00d7 more buffers than SlimGuard.<\/jats:p>","DOI":"10.1145\/3626787","type":"journal-article","created":{"date-parts":[[2023,12,12]],"date-time":"2023-12-12T15:20:29Z","timestamp":1702394429000},"page":"1-26","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["GuaNary: Efficient Buffer Overflow Detection In Virtualized Clouds Using Intel EPT-based Sub-Page Write Protection Support"],"prefix":"10.1145","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3723-6581","authenticated-orcid":false,"given":"Stella","family":"Bitchebe","sequence":"first","affiliation":[{"name":"McGill University, Montreal, PQ, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-2569-5741","authenticated-orcid":false,"given":"Yves","family":"Kone","sequence":"additional","affiliation":[{"name":"IRIT, Toulouse, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7781-1299","authenticated-orcid":false,"given":"Pierre","family":"Olivier","sequence":"additional","affiliation":[{"name":"The University of Manchester, Manchester, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1046-3554","authenticated-orcid":false,"given":"Jalil","family":"Boukhobza","sequence":"additional","affiliation":[{"name":"ENSTA Bretagne, Brest, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3812-3546","authenticated-orcid":false,"given":"Y\u00e9rom-David","family":"Bromberg","sequence":"additional","affiliation":[{"name":"University of Rennes, INRIA, Rennes, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0978-2155","authenticated-orcid":false,"given":"Daniel","family":"Hagimont","sequence":"additional","affiliation":[{"name":"University of Toulouse, Toulouse, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7789-8400","authenticated-orcid":false,"given":"Alain","family":"Tchana","sequence":"additional","affiliation":[{"name":"Grenoble INP, Grenoble, France"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,12,12]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"[n. d.]. Checkpoint Restore In Userspace. https:\/\/criu.org\/Main_Page. Accessed: 2023-03-09."},{"key":"e_1_2_1_2_1","unstructured":"[n. d.]. Chunk Overlap Attack. https:\/\/ctf-wiki.mahaloz.re\/pwn\/linux\/glibc-heap\/chunk_extend_overlapping\/. Accessed: 2022-05--29."},{"key":"e_1_2_1_3_1","unstructured":"[n. d.]. Fast Bin Attack. https:\/\/guyinatuxedo.github.io\/28-fastbin_attack\/explanation_fastbinAttack\/index.html. Accessed: 2022-05--29."},{"key":"e_1_2_1_4_1","unstructured":"[n. d.]. A garbage collector for c and c. https:\/\/www.hboehm.info\/gc\/. Accessed: 2023-03-09."},{"key":"e_1_2_1_5_1","unstructured":"[n. d.]. Github : Security Vulnerabilities. https:\/\/github.com\/GrapheneOS\/hardened_malloc."},{"key":"e_1_2_1_6_1","unstructured":"[n. d.]. The OpenBSD project. https:\/\/www.openbsd.org\/. Accessed: 2022-04--24."},{"key":"e_1_2_1_7_1","unstructured":"[n. d.]. Scudo Hardened Allocator. https:\/\/microsoft.github.io\/mimalloc\/."},{"key":"e_1_2_1_8_1","unstructured":"[n. d.]. Unlink Exploit. https:\/\/heap-exploitation.dhavalkapil.com\/attacks\/unlink_exploit. Accessed: 2022-05--29."},{"key":"e_1_2_1_9_1","unstructured":"2015. Page-Modification Logging for Virtual-Machine Monitor. https:\/\/docplayer.net\/9615410-Page-modification-logging-for-virtual-machine-monitor-white-paper.html."},{"key":"e_1_2_1_10_1","unstructured":"2015. [PATCH 0\/6] KVM: VMX: Page Modification Logging (PML) support. https:\/\/www.spinics.net\/lists\/kvm\/msg112904.html."},{"key":"e_1_2_1_11_1","unstructured":"2017. Intel EPT-Based Sub-page Write Protection Support. https:\/\/lwn.net\/Articles\/736322\/."},{"key":"e_1_2_1_12_1","unstructured":"2017. Xen Project 4.10 Release Notes. https:\/\/wiki.xenproject.org\/wiki\/Xen_Project_4.10_Release_Notes."},{"key":"e_1_2_1_13_1","unstructured":"2018. Intel's new virtualization features on Xeon platforms. https:\/\/bit.ly\/3g9SFP8."},{"key":"e_1_2_1_14_1","unstructured":"2019. Isolation Alloc. https:\/\/github.com\/GrapheneOS\/hardened_malloc."},{"key":"e_1_2_1_15_1","unstructured":"2019. mi-malloc general purpose allocator. https:\/\/microsoft.github.io\/mimalloc\/."},{"key":"e_1_2_1_16_1","unstructured":"2019. A proactive approach to more secure code. https:\/\/msrc-blog.microsoft.com\/2019\/07\/16\/a-proactive-approach-to-more-secure-code\/."},{"key":"e_1_2_1_17_1","unstructured":"2020. Enable Sub-Page Write Protection Support. https:\/\/lwn.net\/Articles\/810033\/."},{"key":"e_1_2_1_18_1","unstructured":"2021. Google Security Blog: An update on Memory Safety in Chrome. https:\/\/security.googleblog.com\/2021\/09\/an-update-on-memory-safety-in-chrome.html."},{"key":"e_1_2_1_19_1","unstructured":"2022. 2021 CWE Top 25 Most Dangerous Software Weaknesses. https:\/\/www.sans.org\/top25-software-errors."},{"key":"e_1_2_1_20_1","unstructured":"2022. Intel MPX Support Is Dead With Linux 5.6. https:\/\/www.phoronix.com\/news\/Intel-MPX-Is-Dead."},{"key":"e_1_2_1_21_1","unstructured":"2022. Olden benchmarks. https:\/\/github.com\/compor\/olden."},{"key":"e_1_2_1_22_1","unstructured":"2023. 2022 CWE Top 25 Most Dangerous Software Weaknesses. https:\/\/cwe.mitre.org\/top25\/archive\/2023\/2023_top25_list.html."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00058"},{"key":"e_1_2_1_24_1","volume-title":"Cling: A Memory Allocator to Mitigate Dangling Pointers. 177--192.","author":"Periklis Akritidis","year":"2010","unstructured":"Akritidis and Periklis. 2010. Cling: A Memory Allocator to Mitigate Dangling Pointers. 177--192."},{"key":"e_1_2_1_25_1","volume-title":"USENIX Security Symposium","volume":"10","author":"Akritidis Periklis","year":"2009","unstructured":"Periklis Akritidis, Manuel Costa, Miguel Castro, and Steven Hand. 2009. Baggy Bounds Checking: An Efficient and Backwards-Compatible Defense against Out-of-Bounds Errors.. In USENIX Security Symposium, Vol. 10."},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/178243.178446"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945462"},{"key":"e_1_2_1_28_1","volume-title":"10th USENIX Symposium on Operating Systems Design and Implementation (OSDI 12)","author":"Belay Adam","year":"2012","unstructured":"Adam Belay, Andrea Bittau, Ali Mashtizadeh, David Terei, David Mazi\u00e8res, and Christos Kozyrakis. 2012. Dune: Safe User-level Access to Privileged CPU Features. In 10th USENIX Symposium on Operating Systems Design and Implementation (OSDI 12). USENIX Association, Hollywood, CA, 335--348. https:\/\/www.usenix.org\/conference\/osdi12\/technical-sessions\/presentation\/belay"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/1454115.1454128"},{"key":"e_1_2_1_30_1","volume-title":"Proceedings of the International Conference on High Performance Computing, Networking, Storage and Analysis","author":"Bitchebe Stella","year":"2022","unstructured":"Stella Bitchebe and Alain Tchana. 2022. Out of Hypervisor (OoH): Efficient Dirty Page Tracking in Userspace Using Hardware Virtualization Features. In Proceedings of the International Conference on High Performance Computing, Networking, Storage and Analysis (Dallas, Texas) (SC '22). IEEE Press, Article 87, 14 pages."},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1555860.1555866"},{"key":"e_1_2_1_32_1","volume-title":"StackGuard: Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks. In 7th USENIX Security Symposium (USENIX Security 98)","author":"Cowan Crispin","year":"1998","unstructured":"Crispin Cowan, Calton Pu, Dave Maier, Jonathan Walpole, Peat Bakke, Steve Beattie, Aaron Grier, Perry Wagle, Qian Zhang, and Heather Hinton. 1998. StackGuard: Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks. In 7th USENIX Security Symposium (USENIX Security 98). USENIX Association, San Antonio, TX. https:\/\/www.usenix.org\/conference\/7th-usenix-security-symposium\/stackguard-automatic-adaptive-detection-and-prevention"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/365230.365252"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3322205.3311076"},{"key":"e_1_2_1_35_1","unstructured":"Ulrich Drepper. 2007. What Every Programmer Should Know About Memory. drepper@redhat.com."},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/2892208.2892212"},{"key":"e_1_2_1_37_1","unstructured":"Intel. 2022. . Vol. 3C. 3849--3865 pages. https:\/\/cdrdv2.intel.com\/v1\/dl\/getContent\/671200"},{"key":"e_1_2_1_38_1","volume-title":"USENIX Annual Technical Conference, General Track. 275--288","author":"Jim Trevor","year":"2002","unstructured":"Trevor Jim, J Gregory Morrisett, Dan Grossman, Michael W Hicks, James Cheney, and Yanling Wang. 2002. Cyclone: a safe dialect of C.. In USENIX Annual Technical Conference, General Track. 275--288."},{"key":"e_1_2_1_39_1","unstructured":"Alexandre J. P. Joannou. 2020. High-performance memory safety: optimizing the CHERI capability machine. Technical Report UCAM-CL-TR-936. Computer Laboratory."},{"key":"e_1_2_1_40_1","volume-title":"AADEBUG","volume":"97","author":"Jones Richard WM","year":"1997","unstructured":"Richard WM Jones and Paul HJ Kelly. 1997. Backwards-Compatible Bounds Checking for Arrays and Pointers in C Programs.. In AADEBUG, Vol. 97. Citeseer, 13--26."},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3064176.3064217"},{"volume-title":"Proceedings of the Thirteenth EuroSys Conference. 1--14","author":"Kroes Taddeus","key":"e_1_2_1_42_1","unstructured":"Taddeus Kroes, Koen Koning, Erik van der Kouwe, Herbert Bos, and Cristiano Giuffrida. 2018. Delta pointers: Buffer overflow checks without the checks. In Proceedings of the Thirteenth EuroSys Conference. 1--14."},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516713"},{"key":"e_1_2_1_44_1","unstructured":"Byoungyoung Lee Chengyu Song Yeongjin Jang Tielei Wang Taesoo Kim Long Lu and Wenke Lee. 2015. Preventing Use-after-free with Dangling Pointers Nullification. In NDSS."},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2872887.2750406"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3361525.3361532"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3416533"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813690"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.17"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3302424.3303946"},{"key":"e_1_2_1_51_1","volume-title":"Proceedings of the 2009 European BSD Conference","volume":"9","author":"Moerbeek Otto","year":"2009","unstructured":"Otto Moerbeek. 2009. A new malloc (3) for OpenBSD. In Proceedings of the 2009 European BSD Conference, Vol. 9."},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542476.1542504"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/503272.503286"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250746"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866371"},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3224423"},{"key":"e_1_2_1_57_1","first-page":"159","article-title":"A Practical Dynamic Buffer Overflow Detector","volume":"4","author":"Ruwase Olatunji","year":"2004","unstructured":"Olatunji Ruwase and Monica S Lam. 2004. A Practical Dynamic Buffer Overflow Detector.. In NDSS, Vol. 4. 159--169.","journal-title":"NDSS"},{"key":"e_1_2_1_58_1","volume-title":"2012 USENIX Annual Technical Conference (USENIX ATC 12)","author":"Serebryany Konstantin","year":"2012","unstructured":"Konstantin Serebryany, Derek Bruening, Alexander Potapenko, and Dmitriy Vyukov. 2012. {AddressSanitizer}: A Fast Address Sanity Checker. In 2012 USENIX Annual Technical Conference (USENIX ATC 12). 309--318."},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653720"},{"key":"e_1_2_1_60_1","volume-title":"Deconstructing Xen. In Network and Distributed System Security Symposium.","author":"Shi Le","year":"2017","unstructured":"Le Shi, Yuming Wu, Yubin Xia, Nathan Dautenhahn, Haibo Chen, Binyu Zang, and Jinming Li. 2017. Deconstructing Xen. In Network and Distributed System Security Symposium."},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133957"},{"key":"e_1_2_1_62_1","volume-title":"Guarder: A Tunable Secure Allocator. In 27th USENIX Security Symposium (USENIX Security 18)","author":"Silvestro Sam","year":"2018","unstructured":"Sam Silvestro, Hongyu Liu, Tianyi Liu, Zhiqiang Lin, and Tongping Liu. 2018. Guarder: A Tunable Secure Allocator. In 27th USENIX Security Symposium (USENIX Security 18). USENIX Association, Baltimore, MD, 117--133. https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/silvestro"},{"key":"e_1_2_1_63_1","unstructured":"Richard Lee Sites. 2022. Understanding Software Dynamics. Pearson Education."},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.13"},{"key":"e_1_2_1_65_1","volume-title":"SafeHidden: An Efficient and Secure Information Hiding Technique Using Re-randomization. In USENIX Security Symposium.","author":"Wang Zhe","year":"2019","unstructured":"Zhe Wang, Chenggang Wu, Yinqian Zhang, Bowen Tang, P. Yew, Mengyao Xie, Yuanming Lai, Yan Kang, Yueqiang Cheng, and Zhiping Shi. 2019. SafeHidden: An Efficient and Secure Information Hiding Technique Using Re-randomization. In USENIX Security Symposium."},{"key":"e_1_2_1_66_1","volume-title":"Hale","author":"Wanninger Nicholas","year":"2021","unstructured":"Nicholas Wanninger, Joshua J. Bowden, and Kyle C. Hale. 2021. Virtines: Virtualization at Function Call Granularity. CoRR abs\/2104.11324 (2021). arXiv:2104.11324 https:\/\/arxiv.org\/abs\/2104.11324"},{"key":"e_1_2_1_67_1","unstructured":"Robert N. M. Watson Alexander Richardson Brooks Davis John Baldwin David Chisnall Jessica Clarke Nathaniel Filardo Simon W. Moore Edward Napierala Peter Sewell and Peter G. Neumann. 2020. CHERI C\/C Programming Guide. Technical Report UCAM-CL-TR-947. Computer Laboratory."},{"key":"e_1_2_1_68_1","volume-title":"Preventing Use-After-Free Attacks with Fast Forward Allocation. In 30th USENIX Security Symposium (USENIX Security 21)","author":"Wickman Brian","year":"2021","unstructured":"Brian Wickman, Hong Hu, Insu Yun, DaeHee Jang, JungWon Lim, Sanidhya Kashyap, and Taesoo Kim. 2021. Preventing Use-After-Free Attacks with Fast Forward Allocation. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, 2453--2470. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/wickman"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/2678373.2665740"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484740"}],"container-title":["Proceedings of the ACM on Measurement and Analysis of Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3626787","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3626787","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T00:13:53Z","timestamp":1755908033000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3626787"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,7]]},"references-count":70,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2023,12,7]]}},"alternative-id":["10.1145\/3626787"],"URL":"https:\/\/doi.org\/10.1145\/3626787","relation":{},"ISSN":["2476-1249"],"issn-type":[{"type":"electronic","value":"2476-1249"}],"subject":[],"published":{"date-parts":[[2023,12,7]]},"assertion":[{"value":"2023-12-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}