FlexFilt: Towards Flexible Instruction Filtering for Security

FlexFilt: Towards Flexible Instruction Filtering for Security
复制标题

DOI:
10.1145/3485832.3488019
复制
发表时间:
2021-12
期刊:
Proceedings of the 37th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Leila Delshadtehrani;Sadullah Canakci;William Blair;Manuel Egele;A. Joshi
Leila Delshadtehrani;Sadullah Canakci;William Blair;Manuel Egele;A. Joshi
中科院分区:
其他
文献类型:
--
作者:
Leila Delshadtehrani;Sadullah Canakci;William Blair;Manuel Egele;A. Joshi

文献摘要

相似文献

随着软件应用程序复杂性的增加,对进程内存储器隔离的需求也在不断增长。现代处理器中的商业上可用的进程内存储器隔离机制,例如,英特尔的内存保护键,在效率和安全保证之间进行权衡。最近,研究人员倾向于利用安全保证较低的功能来进行进程内内存隔离。随后,他们依靠二进制扫描和运行时二进制重写来防止执行不安全的指令,这提高了安全性保证。这样的进程内存储器隔离机制不是必须防止在代码的不可信部分中执行不安全指令的唯一安全解决方案。事实上,我们在各种其他安全解决方案中发现了类似的需求。虽然可以利用二进制扫描和运行时二进制重写方法来解决这一要求,但有效地实现这些方法是具有挑战性的。在本文中,我们提出了一个有效的和灵活的硬件辅助功能的运行时过滤用户指定的指令。这种灵活的功能称为FlexFilt,有助于保护各种基于隔离的机制。FlexFilt使软件开发人员能够创建多达16个指令域,其中每个指令域都可以配置为过滤用户指定指令的执行。除了过滤非特权指令外,FlexFilt还能够过滤特权指令。为了说明FlexFilt与二进制扫描方法相比的有效性,我们测量了在浏览各种网页时扫描JIT编译代码所引起的开销。我们通过在RISC-V Rocket内核上实现我们的设计,为其提供Linux内核支持,并在FPGA上对我们的完整设计进行原型设计,来证明FlexFilt的可行性。
As the complexity of software applications increases, there has been a growing demand for intra-process memory isolation. The commercially available intra-process memory isolation mechanisms in modern processors, e.g., Intel’s memory protection keys, trade-off between efficiency and security guarantees. Recently, researchers have tended to leverage the features with low security guarantees for intra-process memory isolation. Subsequently, they have relied on binary scanning and runtime binary rewriting to prevent the execution of unsafe instructions, which improves the security guarantees. Such intra-process memory isolation mechanisms are not the only security solutions that have to prevent the execution of unsafe instructions in untrusted parts of the code. In fact, we identify a similar requirement in a variety of other security solutions. Although binary scanning and runtime binary rewriting approaches can be leveraged to address this requirement, it is challenging to efficiently implement these approaches. In this paper, we propose an efficient and flexible hardware-assisted feature for runtime filtering of user-specified instructions. This flexible feature, called FlexFilt, assists with securing various isolation-based mechanisms. FlexFilt enables the software developer to create up to 16 instruction domains, where each instruction domain can be configured to filter the execution of user-specified instructions. In addition to filtering unprivileged instructions, FlexFilt is capable of filtering privileged instructions. To illustrate the effectiveness of FlexFilt compared to binary scanning approaches, we measure the overhead caused by scanning the JIT compiled code while browsing various webpages. We demonstrate the feasibility of FlexFilt by implementing our design on the RISC-V Rocket core, providing the Linux kernel support for it, and prototyping our full design on an FPGA.