Memory protection for system software isolation
Memory protection for system software isolation
批准号:
2105211
负责人:
金额:
$0.0万
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2018
资助国家:
英国
项目状态:
已结题
起止时间:
2018 至 --
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Memory vulnerabilities have been a recurrent challenge in systems security. Exploits are targeting increasingly lower levels of abstraction in the system stack (e.g. the OS kernel and firmware), the root of trust on which the user space relies. The goal of this PhD is to investigate and evaluate different approaches to achieving memory safety at a lower level in order to ensure a secure and isolated stack and in turn a more trustworthy user space. One such approach is to leverage memory safe languages such as Rust, which takes advantage of its ownership model to assign an owner to all values in scope, and hence facilitate safe referencing and dereferencing of memory addresses. Another approach is to leverage new hardware Instruction Set Architecture (ISA) extensions. For instance CHERI, a hybrid capability ISA extension for RISC architectures. It enables fault isolation in hardware by combining conventional ISA and Memory Management Unit (MMU) design choices with a capability-system model. CHERI capabilities enable fine-grained memory protection based on the principles of least privilege and intentional use in the execution of software at different levels of the system stack, hence preventing and mitigating vulnerabilities. Finally, initial work so far has explored the use of x86 ISA extension, in the form of Intel's memory protection extensions (MPX), to protect system software inside trusted execution environments (TEEs). We will explore the thesis that such approaches, both individually and in combination, can prevent and mitigate vulnerabilities in security-critical system software
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
加密/签名的密钥泄露保护机制研究
-
批准号:60970111
-
项目类别:面上项目
-
资助金额:33.0万元
-
批准年份:2009
-
负责人:陈克非
-
依托单位: