首页> 外文会议>Proceedings of the 8th USENIX Symposium on Operating Systems Design and Implementation >Hardware Enforcement of Application Security Policies Using Tagged Memory
【24h】

Hardware Enforcement of Application Security Policies Using Tagged Memory

机译:使用标记内存的应用程序安全策略的硬件实施

获取原文
获取原文并翻译 | 示例

摘要

Computers are notoriously insecure, in part because application security policies do not map well onto traditional protection mechanisms such as Unix user accounts or hardware page tables. Recent work has shown that application policies can be expressed in terms of information flow restrictions and enforced in an OS kernel, providing a strong assurance of security. This paper shows that enforcement of these policies can be pushed largely into the processor itself, by using tagged memory support, which can provide stronger security guarantees by enforcing application security even if the OS kernel is compromised. We present the Loki tagged memory architecture, along with a novel operating system structure that takes advantage of tagged memory to enforce application security policies in hardware. We built a full-system prototype of Loki by modifying a synthesizable SPARC core, mapping it to an FPGA board, and porting HiStar, a Unix-like operating system, to run on it. One result is that Loki allows HiStar, an OS already designed to have a small trusted kernel, to further reduce the amount of trusted code by a factor of two, and to enforce security despite kernel compromises. Using various workloads, we also demonstrate that HiStar running on Loki incurs a low performance overhead.
机译:众所周知,计算机是不安全的,部分原因是应用程序安全策略无法很好地映射到传统的保护机制(例如Unix用户帐户或硬件页表)上。最近的工作表明,应用程序策略可以按照信息流限制来表达,并可以在OS内核中强制执行,从而提供了强大的安全性保证。本文显示,通过使用标记的内存支持,可以将这些策略的执行大部分推入处理器本身,即使操作系统内核受到威胁,也可以通过强制应用程序安全性来提供更强的安全性保证。我们介绍Loki标记内存架构,以及利用标记内存在硬件中实施应用程序安全策略的新颖操作系统结构。通过修改可综合的SPARC内核,将其映射到FPGA板并移植HiUnix(一种类似Unix的操作系统)在其上运行,我们构建了Loki的完整系统原型。结果是Loki允许HiStar(一种已经设计成具有小的受信任内核的操作系统)将受信任代码的数量进一步减少了两倍,并且尽管内核受到损害也可以强制执行安全性。使用各种工作负载,我们还演示了在Loki上运行的HiStar会产生较低的性能开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号