Kernel extension verification is untenable

Kernel extension verification is untenable
复制标题

内核扩展验证站不住脚

DOI:
10.1145/3593856.3595892
复制
发表时间:
2023
期刊:
ACM
影响因子:
--
通讯作者:
Xu, Tianyin
Xu, Tianyin
中科院分区:
--
文献类型:
--
作者:
Jia, Jinghao;Sahu, Raj;Oswald, Adam;Williams, Dan;Le, Michael V.;Xu, Tianyin

文献摘要

参考文献

被引文献

相似文献

经过验证的eBPF字节码的出现正在开创一个安全内核扩展的新时代。在本文中,我们认为eBPF的验证器-其安全保证的来源-已经成为一种责任。除了众所周知的错误和漏洞所产生的复杂性和特设性质的内核验证程序,我们强调一个令人关注的趋势,其中逃生舱口不安全的内核函数(在形式ofhelper函数)正在引入绕过验证程序施加的限制的表现力,不幸的是,也绕过其安全保证。我们提出了安全的内核扩展框架,不仅使用静态的平衡,但也轻量级的运行时技术。我们描述了一个以安全Rust中的内核扩展为中心的设计,它将消除对内核内验证器的需求,提高表现力,减少逃逸舱口,并最终提高内核扩展的安全性。
The emergence of verified eBPF bytecode is ushering in a new era of safe kernel extensions. In this paper, we argue that eBPF's verifier---the source of its safety guarantees---has become a liability. In addition to the well-known bugs and vulnerabilities stemming from the complexity and ad hoc nature of the in-kernel verifier, we highlight a concerning trend in which escape hatches to unsafe kernel functions (in the form ofhelper functions) are being introduced to bypass verifier-imposed limitations on expressiveness, unfortunately also bypassing its safety guarantees. We propose safe kernel extension frameworks using a balance of not just static but also lightweight runtime techniques. We describe a design centered around kernel extensions in safe Rust that will eliminate the need of the in-kernel verifier, improve expressiveness, allow for reduced escape hatches, and ultimately improve the safety of kernel extensions.
MOAT:迈向安全的 BPF 内核扩展
DOI: 10.48550/arxiv.2301.13421
发表时间: 2023
期刊: ArXiv
影响因子: --
作者:
Hongyi Lu;Shuai Wang;Yechang Wu;Wanning He;Fengwei Zhang
通讯作者: Fengwei Zhang
用三态数进行可靠、精确、快速的抽象解释
DOI: 10.1109/cgo53902.2022.9741267
发表时间: 2022
期刊: CGO '22: Proceedings of the 20th IEEE/ACM International Symposium on Code Generation and Optimization
影响因子: --
作者:
Vishwanathan, Harishankar;Shachnai, Matan;Narayana, Srinivas;Nagarakatte, Santosh
通讯作者: Nagarakatte, Santosh
锈带
DOI: --
发表时间: 2018
期刊: The Blackwell Encyclopedia of Sociology
影响因子: --
作者:
G
通讯作者: G
DOI: --
发表时间: 2020
期刊: --
影响因子: --
作者:
Vikram Narayanan;Tianjiao Huang;David Detweiler;Daniel M. Appel;Zhaofeng Li;Gerd Zellweger;A. Burtsev
通讯作者: Vikram Narayanan;Tianjiao Huang;David Detweiler;Daniel M. Appel;Zhaofeng Li;Gerd Zellweger;A. Burtsev
DOI: --
发表时间: 2022
期刊: 2022 IEEE International Conference on Cluster Computing (CLUSTER)
影响因子: --
作者:
Yuhong Zhong;Hao Li;Y. Wu;Ioannis Zarkadas;Jeffrey Tao;Evan Mesterhazy;Michael Makris;Junfeng Yang;Amy Tai;Ryan Stutsman;Asaf Cidon
通讯作者: Yuhong Zhong;Hao Li;Y. Wu;Ioannis Zarkadas;Jeffrey Tao;Evan Mesterhazy;Michael Makris;Junfeng Yang;Amy Tai;Ryan Stutsman;Asaf Cidon