Skip to content
Open access

PMO Checker: A Framework for Protecting Persistent Memory Objects Against Security Attacks

Aug 2026 · ACM Transactions on Architecture and Code Optimization (TACO) · Vol 23, pp. 1-25 · 0 citations · 43 references

TL;DR

This work presents PMO Checker, a comprehensive framework for detecting and recovering from security attacks, which includes various invariant checking and checkpointing schemes and is implemented on a real platform with Intel Optane PMem memory.

Abstract

As a new abstraction to manage persistent data in non-volatile memory, Persistent Memory Objects (PMOs) hold (pointer-rich) data structures that can be shared among processes over many runs and system boots. While convenient and fast, such sharing opens up a new class of attacks that attempt to break inter-process isolation, allowing the attacker to compromise a non-vulnerable process through a different process and a shared PMO. Due to the difficulty in completely preventing or avoiding security attacks, we present PMO Checker, a comprehensive framework for detecting and recovering from them. Our framework includes various invariant checking and checkpointing schemes. We implement them on a real system with Linux kernel on a real platform with Intel Optane PMem memory. Our evaluation shows the effectiveness of the attack detection and various performance optimizations that keep the overheads low.

Read PDF

Similar papers

Aug 2026

PMDangNull: Preventing use-After-Free for Persistent Memory Applications

Use-After-Free (UAF) remains one of the most critical security threats affecting C/C++ programs. Moreover, the cross-restart persistence semantics of persistent memory (PM) programming models significantly broaden the UAF attack surface. Existing DRAM-based protection schemes lack crash consistency guarantees, whereas...

Yuquan Chi, Yinjin Fu, Yong-Gang Hu et al. · 0 citations

Melting the Flesh of PHP’s Memory Hardening

It is found that although the new protection measures aimed at stopping popular heap exploit techniques or restricting the exploit strategy space can effectively defend against the exploitation of most vulnerabilities, the attack strategies proposed by this work can still make these vulnerabilities exploitable again.

Yifan Wu, Xiao-Chuan Yu, Zhiyun Qian · 0 citations
Preprint Sep 2026

HermiCache: Enclave-Aware Cache Replacement for Trusted Execution Environments

Trusted Execution Environments (TEEs) protect enclave memory from untrusted software but remain vulnerable to cache-based side-channel attacks due to shared microarchitectural resources. Existing countermeasures use techniques such as cache partitioning or randomization: these solutions are not ideal if a designer want...

Oussama Elmnaouri, Pascal Cotret, Vianney Lapôtre et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.