x86_64禁用分段后,控制流完整性中受保护阴影栈有何替代实现机制?
Implementing Protected Shadow Stacks on x86_64
Great question! It’s true that x86’s protected shadow stacks rely on the LDT and segmentation mechanisms—features that are largely disabled in x86_64 (with only limited exceptions like the FS/GS segments for TLS). But there are several robust alternatives for implementing protected shadow stacks on this architecture, many of which are detailed in recent research papers. Here are the most prominent approaches:
- Hardware-Assisted Shadow Stacks: Intel's Control-Flow Enforcement Technology (CET) and AMD's Shadow Stack Extension (SSE) are purpose-built hardware features for this exact use case. They provide a dedicated, CPU-enforced shadow stack that runs parallel to the regular stack. On
callinstructions, the CPU automatically pushes return addresses to both stacks; onret, it validates that the addresses match before proceeding. This eliminates most return-oriented programming (ROP) attacks at the hardware level, making it the most secure option available today. - Software-Based Shadow Stacks with Memory Protection: You can implement a shadow stack in a separate memory region, using OS-level page protections to lock it down. For example, mark the shadow stack as
PROT_READ/PROT_NONEon Linux orPAGE_READONLY/PAGE_NOACCESSon Windows, only temporarily setting it to writable during controlledpushoperations. The MMU enforces these protections, though this approach is more vulnerable to attacks that can manipulate memory permissions compared to hardware solutions. - FS/GS Segment Repurposing: Even though general segmentation is disabled in x86_64, the FS and GS segments are still active for thread-local storage. You can repurpose these segments to point to a shadow stack region, using their hidden descriptor attributes (like segment limits) to restrict access. For instance, setting the segment limit to match the current shadow stack pointer ensures that only valid stack accesses are allowed. This is a hybrid software-hardware approach that leverages x86_64’s remaining segmentation capabilities.
- Virtualization-Based Shadow Stacks: Hypervisors can intercept
callandretinstructions at the virtualization layer, maintaining a shadow stack for each guest process. The hypervisor cross-checks return addresses between the guest’s regular stack and its own shadow stack, blocking any mismatches. This works without specialized hardware, but adds noticeable overhead due to hypervisor interception.
As you mentioned, recent research papers expand on these ideas—some combining multiple mechanisms to cover more attack vectors, or optimizing software-based solutions to reduce overhead while retaining strong security guarantees.
内容的提问来源于stack exchange,提问作者budchan chao
相关产品推荐
相关产品推荐

