Position Paper:Defending Direct Memory Access with CHERI Capabilities

Position Paper:Defending Direct Memory Access with CHERI Capabilities
复制标题

立场文件:利用 CHERI 功能捍卫直接内存访问

DOI:
10.1145/3458903.3458910
复制
发表时间:
2020
期刊:
--
影响因子:
--
通讯作者:
Markettos A
Markettos A
中科院分区:
--
文献类型:
--
作者:
Markettos A

文献摘要

参考文献

被引文献

相似文献

我们提出了新的解决方案,可以有效地解决从可插拔的计算机外围设备和嵌入在片上系统的微控制器的恶意内存访问的问题。这个问题对整个系统的计算机安全构成了严重的威胁。以前的工作表明,现有的防御是不够的,部署不良,部分原因是性能问题。在本文中,我们探讨的威胁及其对系统架构的影响。我们提出了一系列跨不同类型系统的保护技术,从轻量级到重量级。我们认为新兴的能力架构(特别是CHERI保护模型)可以增强保护,并提供一个方便的桥梁来描述软件和硬件组件之间的交互。最后,我们描述了新的计划可能比现有的防御更有效。
We propose new solutions that can efficiently address the problem of malicious memory access from pluggable computer peripherals and microcontrollers embedded within a system-on-chip. This problem represents a serious emerging threat to total-system computer security. Previous work has shown that existing defenses are insufficient and poorly deployed, in part due to performance concerns. In this paper we explore the threat and its implications for system architecture. We propose a range of protection techniques, from lightweight to heavyweight, across different classes of systems. We consider how emerging capability architectures (and specifically the CHERI protection model) can enhance protection and provide a convenient bridge to describe interactions among software and hardware components. Finally, we describe how new schemes may be more efficient than existing defenses.
CHERI Concentrate:实用的压缩功能
DOI: 10.1109/tc.2019.2914037
发表时间: 2019
影响因子: 3.7
作者:
Woodruff J
通讯作者: Woodruff J
DOI: 10.1007/978-3-642-24322-6_22
发表时间: 2010-06
期刊: --
影响因子: --
作者:
Nadav Amit;Muli Ben-Yehuda;Ben-Ami Yassour
通讯作者: Nadav Amit;Muli Ben-Yehuda;Ben-Ami Yassour
DOI: --
发表时间: 2007
期刊: --
影响因子: --
作者:
Muli Ben-Yehuda;J. Xenidis;Michal Ostrowski;Karl Rister;Alexis Bruemmer;L. V. Doorn
通讯作者: Muli Ben-Yehuda;J. Xenidis;Michal Ostrowski;Karl Rister;Alexis Bruemmer;L. V. Doorn
Thunderstrike:适用于 Apple MacBook 的 EFI 固件启动套件
DOI: 10.1145/2757667.2757673
发表时间: 2015
期刊: Proceedings of the 8th ACM International Systems and Storage Conference
影响因子: --
作者:
T. Hudson;L. Rudolph
通讯作者: L. Rudolph
Thunderclap:通过来自不可信外设的 DMA 探索操作系统 IOMMU 保护中的漏洞
DOI: 10.14722/ndss.2019.23194
发表时间: 2019
期刊: --
影响因子: --
作者:
Markettos A
通讯作者: Markettos A