课题基金 / 基金详情

CHERI for Hypervisors and Operating Systems (CHaOS)

CHERI for Hypervisors and Operating Systems (CHaOS)
用于虚拟机管理程序和操作系统 (CHaOS) 的 CHERI
批准号:
EP/V000292/1
负责人:
Robert Watson
金额:
$111.92万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2020
资助国家:
英国
项目状态:
未结题
起止时间:
2020 至 --

项目摘要

项目成果

Robert Watson的其他基金

相似基金

相关文献

中文摘要
翻译
软件分区化是将较大的软件包(如web浏览器或操作系统内核)分解为独立的组件。每个组件都被授予有限的使用系统服务或与其他隔离组件通信的权利。直观地说,从划分中缓解漏洞是基于最小特权原则的,该原则认为,通过最小化所需人员可用的特权集来提高安全性。受损的软件将产生更少的权限,并限制成功攻击者的进一步攻击面。在之前的工作中,我们开发了CHERI,这是RISC指令集架构的一组架构扩展,以支持高效、细粒度的内存保护和可扩展的软件划分。在英国产业战略挑战基金(ISCF)的支持下,Arm正在开发Morello CPU、SoC和主板,这是一款将CHERI原则体现在商业硬件设计中的高端工业级示范产品。与传统的硬件设计相比,该平台具有支持更细粒度和更容易集成的划分支持的潜力。然而,目前用于CHERI的研究软件堆栈几乎完全集中在内存保护上,而不是分区化上——部分原因是与基于CHERI的分区化相关的软件操作模型尚未建立。我们建议设计、原型化和评估新的基于cheri的划分技术,这些技术可用于支持Morello董事会上对现实世界软件的细粒度、可扩展的软件划分,从而对广泛的用例和操作模型建立深刻的理解(以及实际的原型)。CHaOS将在系统软件堆栈中广泛采用软件划分,为许多已知(以及仍待发现的)漏洞类别和影响服务器、桌面、移动和嵌入式系统的利用技术提供强有力的缓解。CHaOS将研究以下假设:(1)CHERI可以支持多种有效的分区操作模型;(2) CHERI划分方法必须迎合系统堆栈上下的实质性差异;(3)对划分的详细阐述将带来关键的实际考虑(例如,与调试有关);(4)进一步完善CHERI(和Morello)架构可能需要作为在这项工作中吸取教训的结果。我们将跨系统软件堆栈探索这些假设:管理程序、通用操作系统内核和用户应用程序。我们现有的用于CHERI内存安全的开源语料库将是我们的起点:FreeBSD内核和用户空间、PostgreSQL数据库和苹果的WebKit。与我们的工业合作伙伴(Arm、谷歌、HPI和微软)一起,我们将扩大我们的调查范围,包括Arm的Morello Android、谷歌的Hafnium管理程序、HPI的打印机软件堆栈和微软的Verona语言运行时。
英文摘要
Software compartmentalisation is the decomposition of larger software packages - such as web browser or OS kernels - into isolated components. Each is granted limited rights to utilize system services or communicate with other isolated components. Intuitively, vulnerability mitigation from compartmentalisation is grounded in the principle of least privilege, which argues that security is improved by minimising the set of privileges available to those required. Compromised software will yield fewer rights and limit further attack surfaces to a successful attacker.In prior work, we have developed CHERI, a set of architectural extensions to RISC instruction-set architectures to support efficient, fine-grained memory protection and scalable software compartmentalisation. Supported by the UK Industrial Strategy Challenge Fund (ISCF), Arm is creating the Morello CPU, SoC, and board, a high-end, industrial-quality demonstrator of the CHERI principles embodied within a commercial hardware design. This platform has the potential to support far more granular and more easily integrated compartmentalization support than convention hardware designs. However, the current research software stacks for CHERI have been almost entirely focused on memory protection rather than compartmentalisation -- in part because the software operational models associated with CHERI-based compartmentalisation have not yet been established.We propose to design, prototype, and evaluate new CHERI-based compartmentalisation techniques usable to support fine-grained, scalable software compartmentalisation of real-world software on the Morello board, building a deep understanding (as well as practical prototypes) spanning a rich range of use cases and operational models. CHaOS will enable extensive adoption of software compartmentalisation in systems software stacks, offering strong mitigation for many known (and also still-to-be-discovered) vulnerability classes and exploit techniques affecting server, desktop, mobile, and embedded systems.CHaOS will investigate the hypotheses that: (1) CHERI can support multiple effective operational models for compartmentalisation; (2) approaches to CHERI compartmentalisation must cater to substantial differences up and down the systems stack; (3) detailed elaboration of compartmentalisation will turn up critical practical considerations (e.g., as relates to debugging); and (4) further refinement of the CHERI (and Morello) architectures may be required as a result of lessons learned in this work.We will explore these hypotheses across the systems software stack: the hypervisor, general-purpose OS kernel, and user applications. Our existing open-source corpus adapted for CHERI memory safety will be our starting point: the FreeBSD kernel and userspace, the PostgreSQL database, and Apple's WebKit. With our industrial partners on this proposal (Arm, Google, HPI, and Microsoft), we will extend our investigation to include Arm's Morello Android, Google's Hafnium hypervisor, HPI's printer software stack, and Microsoft's Verona language runtime.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
The Arm Morello Evaluation Platform-Validating CHERI-Based Security in a High-Performance System
Arm Morello 评估平台 - 在高性能系统中验证基于 CHERI 的安全性
DOI: 10.1109/mm.2023.3264676
发表时间: 2023
期刊: IEEE Micro
影响因子: 3.6
作者: [Grisenthwaite R]
通讯作者: Grisenthwaite R
IOSEC - Protection and Memory Safety for Input/Output Security
  • 批准号:
    EP/R012458/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $65.23万
  • 财政年份:
    2018
  • 负责人:
    Robert Watson
  • 依托单位:
QFC: Quantum Fibre Clock
  • 批准号:
    EP/S000232/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $23.99万
  • 财政年份:
    2018
  • 负责人:
    Robert Watson
  • 依托单位:
FEMTO: FEmtosecond Measurement Technology Options
  • 批准号:
    EP/M508251/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $22.8万
  • 财政年份:
    2015
  • 负责人:
    Robert Watson
  • 依托单位:
SENTINEL: GNSS SErvices Needing Trust In Navigation, Electronics, Location & timing
  • 批准号:
    TS/I00257X/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $27.49万
  • 财政年份:
    2011
  • 负责人:
    Robert Watson
  • 依托单位:
海外基金