Isolating functions at the hardware limit with virtines

Isolating functions at the hardware limit with virtines
复制标题

DOI:
10.1145/3492321.3519553
复制
发表时间:
2021-04
期刊:
Proceedings of the Seventeenth European Conference on Computer Systems
影响因子:
--
通讯作者:
Nicholas C. Wanninger;Josh Bowden;K. Shetty;Ayush Garg;Kyle C. Hale
Nicholas C. Wanninger;Josh Bowden;K. Shetty;Ayush Garg;Kyle C. Hale
中科院分区:
其他
文献类型:
--
作者:
Nicholas C. Wanninger;Josh Bowden;K. Shetty;Ayush Garg;Kyle C. Hale

文献摘要

相似文献

一类重要的应用程序,包括利用第三方库的程序、在数据库中使用用户定义函数的程序以及无服务器应用程序,都受益于以单个函数或函数调用的粒度隔离不受信任代码的执行。然而,现有的隔离机制并不是为这个用例设计的;相反,它们已经适应了这个用例。我们介绍了Virtines,这是一种专门为功能粒度隔离设计的新抽象,并描述了如何通过将硬件虚拟化推向极限来从头开始构建Virtines。在决定哪些函数应该在隔离环境中运行、哪些函数不应该在隔离环境中运行时,Virtines为开发人员提供了细粒度的控制。原始抽象是一个通用的抽象,我们演示了一个原型,它添加了对C语言的扩展。我们详细分析了在隔离的VM中运行单个函数的开销,并在这些发现的指导下,提出了Wasp,这是一个可嵌入的管理程序,允许程序员轻松使用Virtines。我们描述了几个使用单个功能隔离的典型场景,并演示了Virtines可以在这些场景中应用,只需对现有代码库进行几行更改,并具有可接受的减慢。
An important class of applications, including programs that leverage third-party libraries, programs that use user-defined functions in databases, and serverless applications, benefit from isolating the execution of untrusted code at the granularity of individual functions or function invocations. However, existing isolation mechanisms were not designed for this use case; rather, they have been adapted to it. We introduce virtines, a new abstraction designed specifically for function granularity isolation, and describe how we build virtines from the ground up by pushing hardware virtualization to its limits. Virtines give developers fine-grained control in deciding which functions should run in isolated environments, and which should not. The virtine abstraction is a general one, and we demonstrate a prototype that adds extensions to the C language. We present a detailed analysis of the overheads of running individual functions in isolated VMs, and guided by those findings, we present Wasp, an embeddable hypervisor that allows programmers to easily use virtines. We describe several representative scenarios that employ individual function isolation, and demonstrate that virtines can be applied in these scenarios with only a few lines of changes to existing codebases and with acceptable slowdowns.