Fast Intra-kernel Isolation and Security with IskiOS

Fast Intra-kernel Isolation and Security with IskiOS
复制标题

DOI:
10.1145/3471621.3471849
复制
发表时间:
2019-03
期刊:
Proceedings of the 24th International Symposium on Research in Attacks, Intrusions and Defenses
影响因子:
--
通讯作者:
Spyridoula Gravani;Mohammad Hedayati;J. Criswell;M. Scott
Spyridoula Gravani;Mohammad Hedayati;J. Criswell;M. Scott
中科院分区:
其他
文献类型:
--
作者:
Spyridoula Gravani;Mohammad Hedayati;J. Criswell;M. Scott

文献摘要

相似文献

Windows、Linux和MacOS等操作系统的内核容易受到控制流劫持的攻击。防御措施是存在的,但许多需要有效的地址空间内隔离。例如,只执行内存需要对代码段进行读保护,影子堆栈需要防止缓冲区重写。原则上,英特尔的用户空间保护密钥(PKU)可以提供此类防御所需的内核内隔离,但当按设计使用时,它仅适用于用户模式应用程序代码。本文提出了一种非传统的内存保护方法,允许PKU在现有英特尔硬件上的操作系统内核中使用,取代传统的用户/管理程序隔离机制,同时实现高效的内核内隔离。我们称之为内核空间保护密钥(PKK)。为了证明它的实用性和效率,我们提出了一个系统,我们称之为IskiOS:一个Linux变种,具有只执行内存(XOM)和有史以来第一个无竞争的x86-64阴影堆栈。使用LMBench内核微基准测试的实验显示,PKK的几何平均开销约为11%,XOM没有额外的开销。Iskios的影子堆栈使总数达到22%。对于完整的应用程序,Phoronix测试套件的系统基准测试显示PKK和XOM的开销可以忽略不计,影子堆栈的几何平均开销小于5%。
The kernels of operating systems such as Windows, Linux, and MacOS are vulnerable to control-flow hijacking. Defenses exist, but many require efficient intra-address-space isolation. Execute-only memory, for example, requires read protection on code segments, and shadow stacks require protection from buffer overwrites. Intel’s Protection Keys for Userspace (PKU) could, in principle, provide the intra-kernel isolation needed by such defenses, but, when used as designed, it applies only to user-mode application code. This paper presents an unconventional approach to memory protection, allowing PKU to be used within the operating system kernel on existing Intel hardware, replacing the traditional user/supervisor isolation mechanism and, simultaneously, enabling efficient intra-kernel isolation. We call the resulting mechanism Protection Keys for Kernelspace (PKK). To demonstrate its utility and efficiency, we present a system we call IskiOS: a Linux variant featuring execute-only memory (XOM) and the first-ever race-free shadow stacks for x86-64. Experiments with the LMBench kernel microbenchmarks display a geometric mean overhead of about 11% for PKK and no additional overhead for XOM. IskiOS’s shadow stacks bring the total to 22%. For full applications, experiments with the system benchmarks of the Phoronix test suite display negligible overhead for PKK and XOM, and less than 5% geometric mean overhead for shadow stacks.