Analyzing the Overhead of File Protection by Linux Security Modules

Analyzing the Overhead of File Protection by Linux Security Modules
复制标题

分析 Linux 安全模块的文件保护开销

DOI:
10.1145/3433210.3453078
复制
发表时间:
2021
期刊:
2021 ACM Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Jaeger, Trent
Jaeger, Trent
中科院分区:
--
文献类型:
--
作者:
Zhang, Wenhui;Liu, Peng;Jaeger, Trent

文献摘要

参考文献

被引文献

相似文献

多年来,Linux安全模块(LSM)的复杂性一直在增加(例如,Linux v2.6.0中的10,684个钩子对v5.3中的64,018个钩子),授权钩子的数量几乎翻了一番(例如,v2.6.0中的122个钩子对v5.3中的224个钩子)。此外,计算机工业已经看到了硬件方面的巨大进步(例如,内存和处理器频率)。这使得18年前对最小二乘模型进行的评价在今天变得不那么相关。为系统从业者提供最新的LSM度量结果非常重要,这样他们就可以在安全性和性能之间做出谨慎的权衡。本文评估了Linux v5.3.0上文件访问的LSM开销。我们建立了一个LSM的性能评估框架。它有两个部分,一个是LMBench2.5的扩展,用于评估不同安全模块的文件操作开销,另一个是具有可调延迟的安全模块,用于研究策略执行延迟对文件操作端到端延迟的影响。我们发现,当内核与SE Linux挂钩(禁用策略强制)集成时,打开一个文件会看到大约87%(Linux v5.3)的性能下降,而没有集成时,这个数字是27%(Linux v2.4.2)。我们发现,上述降级的性能受到两个部分的影响,策略执行和挂钩放置。为了进一步研究策略执行和钩子放置的影响,我们构建了一个策略测试模块,它重用LSM的钩子放置,同时交替策略执行的延迟。通过此模块,我们能够使用多元线性回归模型定量估计策略实施延迟对文件操作端到端延迟的影响,并统计每个系统调用的策略授权频率。然后,我们讨论和证明的评估结果与静态分析系统调用图。
Over the years, the complexity of the Linux Security Module (LSM) is keeping increasing (e.g. 10,684 LOC in Linux v2.6.0 vs. 64,018 LOC in v5.3), and the count of the authorization hooks is nearly doubled (e.g. 122 hooks in v2.6.0 vs. 224 hooks in v5.3). In addition, the computer industry has seen tremendous advancement in hardware (e.g., memory and processor frequency) in the past decade. These make the previous evaluation on LSM, which was done 18 years ago, less relevant nowadays. It is important to provide up-to-date measurement results of LSM for system practitioners so that they can make prudent trade-offs between security and performance. This work evaluates the overhead of LSM for file accesses on Linux v5.3.0. We build a performance evaluation framework for LSM. It has two parts, an extension of LMBench2.5 to evaluate the overhead of file operations for different security modules, and a security module with tunable latency for policy enforcement to study the impact of the latency of policy enforcement on the end-to-end latency of file operations.In our evaluation, we find opening a file would see about 87% (Linux v5.3) performance drop when the kernel is integrated with SELinux hooks (policy enforcement disabled) than without, while the figure was 27% (Linux v2.4.2). We found that the performance of the above downgrade is affected by two parts, policy enforcement, and hook placement. To further investigate the impact of policy enforcement and hook placement respectively, we build a Policy Testing Module, which reuses hook placements of LSM, while alternating latency of policy enforcement. With this module, we are able to quantitatively estimate the impact of the latency of policy enforcement on the end-to-end latency of file operations by using a multiple linear regression model and count policy authorization frequencies for each syscall. We then discuss and justify the evaluation results with static analysis on syscalls' call graphs.
利用基于LSM的LSMPMON性能评估机制评估安全操作系统的性能
DOI: --
发表时间: 2010
期刊: FGIT-SecTech/DRBC
影响因子: --
作者:
Kenji Yamamoto;Toshihiro Yamauchi
通讯作者: Toshihiro Yamauchi
DOI: --
发表时间: 1995
期刊: STAN
影响因子: --
作者:
Stephen R. Walli
通讯作者: Stephen R. Walli
DOI: 10.1038/srep38835
发表时间: 2016-12-13
期刊: Scientific reports
影响因子: 4.6
作者:
Kaur N;Bahadur J;Panwar V;Singh P;Rathi K;Pal K
通讯作者: Pal K
PolTree:ABAC 中用于做出高效访问决策的数据结构
DOI: 10.1145/3322431.3325102
发表时间: 2019
期刊: Proceedings of the 24th ACM Symposium on Access Control Models and Technologies
影响因子: --
作者:
Nath, Ronit;Das, Saptarshi;Sural, Shamik;Vaidya, Jaideep;Atluri, Vijay
通讯作者: Atluri, Vijay
DOI: --
发表时间: 2010
期刊:
影响因子: --
作者:
James Morris
通讯作者: James Morris