CHERI for Hypervisors and Operating Systems (CHaOS)
CHERI for Hypervisors and Operating Systems (CHaOS)
批准号:
EP/V000292/1
负责人:
Robert Watson
金额:
$111.92万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2020
资助国家:
英国
项目状态:
未结题
起止时间:
2020 至 --
中文摘要
软件划分是将较大的软件包--如Web浏览器或操作系统内核--分解成独立的组件。每个组件都被授予使用系统服务或与其他独立组件通信的有限权限。从直觉上看,从分区中缓解脆弱性是基于最小特权原则,该原则认为,通过将所需的特权集降至最低,可以提高安全性。在以前的工作中,我们开发了Cheri,这是对RISC指令集体系结构的一组体系结构扩展,以支持高效、细粒度的内存保护和可扩展的软件划分。在英国工业战略挑战基金(ISCF)的支持下,ARM正在创造Morello CPU、SoC和电路板,这是商业硬件设计中体现的Cheri原则的高端、工业质量的演示。与常规硬件设计相比,该平台有可能支持更细粒度和更容易集成的分区支持。然而,目前用于Cheri的研究软件堆栈几乎完全集中于内存保护,而不是划分--部分原因是与基于Cheri的划分相关的软件操作模型尚未建立。我们建议设计、原型和评估基于Cheri的新划分技术,这些技术可用于支持Morello板上真实世界软件的细粒度、可扩展的软件划分,建立跨越丰富的用例和操作模型的深刻理解(以及实践原型)。Chaos将在系统软件堆栈中广泛采用软件分区,为许多已知(以及仍有待发现)的漏洞类别提供强有力的缓解,并利用影响服务器、台式机、移动和嵌入式系统的技术。CHaOS将调查以下假设:(1)Cheri可以支持多种有效的分区操作模型;(2)Cheri分区的方法必须迎合系统堆栈上下的显著差异;(3)详细的分区将带来关键的实际考虑因素(例如,与调试相关的);以及(4)根据在这项工作中学到的经验教训,可能需要进一步改进Cheri(和Morello)体系结构。我们将在整个系统软件堆栈中探索这些假设:管理程序、通用操作系统内核和用户应用程序。我们现有的适用于Cheri内存安全的开源语料库将是我们的起点:FreeBSD内核和用户空间、PostgreSQL数据库和Apple的WebKit。与我们的行业合作伙伴(ARM、谷歌、HPI和微软)一起,我们将扩大我们的调查范围,以包括ARM的Morello Android、谷歌的Hafnium管理程序、HPI的打印机软件堆栈和微软的Verona语言运行时。
英文摘要
Software compartmentalisation is the decomposition of larger software packages - such as web browser or OS kernels - into isolated components. Each is granted limited rights to utilize system services or communicate with other isolated components. Intuitively, vulnerability mitigation from compartmentalisation is grounded in the principle of least privilege, which argues that security is improved by minimising the set of privileges available to those required. Compromised software will yield fewer rights and limit further attack surfaces to a successful attacker.In prior work, we have developed CHERI, a set of architectural extensions to RISC instruction-set architectures to support efficient, fine-grained memory protection and scalable software compartmentalisation. Supported by the UK Industrial Strategy Challenge Fund (ISCF), Arm is creating the Morello CPU, SoC, and board, a high-end, industrial-quality demonstrator of the CHERI principles embodied within a commercial hardware design. This platform has the potential to support far more granular and more easily integrated compartmentalization support than convention hardware designs. However, the current research software stacks for CHERI have been almost entirely focused on memory protection rather than compartmentalisation -- in part because the software operational models associated with CHERI-based compartmentalisation have not yet been established.We propose to design, prototype, and evaluate new CHERI-based compartmentalisation techniques usable to support fine-grained, scalable software compartmentalisation of real-world software on the Morello board, building a deep understanding (as well as practical prototypes) spanning a rich range of use cases and operational models. CHaOS will enable extensive adoption of software compartmentalisation in systems software stacks, offering strong mitigation for many known (and also still-to-be-discovered) vulnerability classes and exploit techniques affecting server, desktop, mobile, and embedded systems.CHaOS will investigate the hypotheses that: (1) CHERI can support multiple effective operational models for compartmentalisation; (2) approaches to CHERI compartmentalisation must cater to substantial differences up and down the systems stack; (3) detailed elaboration of compartmentalisation will turn up critical practical considerations (e.g., as relates to debugging); and (4) further refinement of the CHERI (and Morello) architectures may be required as a result of lessons learned in this work.We will explore these hypotheses across the systems software stack: the hypervisor, general-purpose OS kernel, and user applications. Our existing open-source corpus adapted for CHERI memory safety will be our starting point: the FreeBSD kernel and userspace, the PostgreSQL database, and Apple's WebKit. With our industrial partners on this proposal (Arm, Google, HPI, and Microsoft), we will extend our investigation to include Arm's Morello Android, Google's Hafnium hypervisor, HPI's printer software stack, and Microsoft's Verona language runtime.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
The Arm Morello Evaluation Platform-Validating CHERI-Based Security in a High-Performance System
Arm Morello 评估平台 - 在高性能系统中验证基于 CHERI 的安全性
DOI:
10.1109/mm.2023.3264676
发表时间:
2023
期刊:
IEEE Micro
影响因子:
3.6
作者:
[Grisenthwaite R]
通讯作者:
Grisenthwaite R
IOSEC - Protection and Memory Safety for Input/Output Security
-
批准号:EP/R012458/1
-
项目类别:Research Grant
-
资助金额:$65.23万
-
财政年份:2018
-
负责人:Robert Watson
-
依托单位:
QFC: Quantum Fibre Clock
-
批准号:EP/S000232/1
-
项目类别:Research Grant
-
资助金额:$23.99万
-
财政年份:2018
-
负责人:Robert Watson
-
依托单位:
FEMTO: FEmtosecond Measurement Technology Options
-
批准号:EP/M508251/1
-
项目类别:Research Grant
-
资助金额:$22.8万
-
财政年份:2015
-
负责人:Robert Watson
-
依托单位:
SENTINEL: GNSS SErvices Needing Trust In Navigation, Electronics, Location & timing
-
批准号:TS/I00257X/1
-
项目类别:Research Grant
-
资助金额:$27.49万
-
财政年份:2011
-
负责人:Robert Watson
-
依托单位:
The utilization of digital television and radio signals for atmospheric science
-
批准号:NE/I000933/1
-
项目类别:Research Grant
-
资助金额:$13.64万
-
财政年份:2010
-
负责人:Robert Watson
-
依托单位:
A study of the climatic dependency of rainfall rate dynamics for use in the design of fade mitigation techniques
-
批准号:EP/D057930/1
-
项目类别:Research Grant
-
资助金额:$3.88万
-
财政年份:2006
-
负责人:Robert Watson
-
依托单位:
海外基金