kGuard: Lightweight Kernel Protection against Return-to-user Attacks
Vasileios P. Kemerlis, Georgios Portokalidis, Angelos D. Keromytis · 2012
Return-to-user (ret2usr) attacks exploit the operating sys-tem kernel, enabling local users to hijack privileged ex-ecution paths and execute arbitrary code with elevated privileges. Current defenses have proven to be inade-quate, as they have been repeatedly circumvented, in-cur considerable overhead, or rely on extended hypervi-sors and special hardware features. We present kGuard, a compiler plugin that augments the kernel with com-pact inline guards, which prevent ret2usr with low per-formance and space overhead. kGuard can be used with any operating system that features a weak separation be-tween kernel and user space, requires no modifications to the OS, and is applicable to both 32- and 64-bit ar-chitectures. Our evaluation demonstrates that Linux ker-nels compiled with kGuard become impervious to a va-riety of control-flow hijacking exploits. kGuard exhibits lower overhead than previous work, imposing on average an overhead of 11.4 % on system call and I/O latency on x86 OSs, and 10.3 % on x86-64. The size of a kGuard-protected kernel grows between 3.5 % and 5.6%, due to the inserted checks, while the impact on real-life appli-cations is minimal (≤1%). 1