Hardware-assisted Live Kernel Function Updating on Intel Platforms

Hardware-assisted Live Kernel Function Updating on Intel Platforms
复制标题

DOI:
10.1109/tdsc.2023.3300101
复制
发表时间:
2024-07
影响因子:
7.3
通讯作者:
Lei Zhou;Fengwei Zhang;Kevin Leach;Xuhua Ding;Zhenyu Ning;Guojun Wang;Jidong Xiao
Lei Zhou;Fengwei Zhang;Kevin Leach;Xuhua Ding;Zhenyu Ning;Guojun Wang;Jidong Xiao
中科院分区:
计算机科学2区
文献类型:
--
作者:
Lei Zhou;Fengwei Zhang;Kevin Leach;Xuhua Ding;Zhenyu Ning;Guojun Wang;Jidong Xiao

文献摘要

相似文献

传统的内核更新,如完善的维护和漏洞修补,需要关闭系统,中断应用程序的连续执行。企业和研究人员已经提出了各种实时更新技术来修补内核,减少停机时间,以减少有用的内核的损失。然而,现有的内核实时更新技术要么依赖于来自目标OS的特定支持,要么部署在虚拟化环境中(即,在虚拟机中运行的系统)。在这篇文章中,我们介绍了KShot,一个硬件辅助的实时和安全的内核函数更新机制,用于本地操作系统。通过利用x86 SMM和英特尔SGX,KShot可在硬件辅助的可信执行环境中运行,并在二进制级别更新内核函数,而无需依赖底层操作系统支持。我们证明了KShot的适用性,成功地修补关键的内核漏洞,升级基本内核功能和驱动程序几乎立即和透明。我们的实验结果表明,KShot只会导致70微秒的停机时间来更新一个1字节的二进制文件和18 MB的内存开销。
Traditional kernel updates such as perfective maintenance and vulnerability patching requires shutting the system down, disrupting continuous execution of applications. Enterprises and researchers have proposed various live updating techniques to patch the kernel with lower downtime to reduce the loss of useful uptime. However, existing kernel live update techniques either rely on specific support from the target OS, or are deployed in virtualized environments (i.e., systems running in virtual machines). In this article we present KShot, a hardware-assisted live and secure kernel function update mechanism for native operating systems. By leveraging x86 SMM and Intel SGX, KShot runs in hardware-assisted Trusted Execution Environments and updates kernel functions at the binary-level without relying on the underlying OS support. We demonstrate the applicability of KShot by successfully patching critical kernel vulnerabilities, upgrading base kernel functions and drivers nearly instantly and transparently. Our experimental results show that KShot incurs merely 70 microseconds downtime to update a one kilobyte binary and 18 MB memory overhead.