Reducing the TCB of SGX-Oriented LibOSes at Runtime
Donghui Yu, Dahan Pan, Fengwei Zhang, Haoran Fang, Ya Fang, Yuanyuan Zhang
Abstract
Intel Software Guard Extensions (SGX) provides a trusted execution environment (TEE) for applications to protect runtime code and data from the untrusted environment. All code residing in the enclave, including LibOSes and the libraries, is all taken into the Trusted Computing Base (TCB). The TCB size closely correlates with the potential vulnerabilities and the system’s attack surface. Vulnerabilities in the enclave can tamper with the control flow of the enclave program and potentially lead to data breaches. Existing SGX frameworks present a dilemma: either include a large LibOS in the enclave to ensure functionality, which inflates the TCB and attack surface, or move the OS out for a minimal TCB, which severely restricts application support or incurs high overhead, insecure interactions with the untrusted world. In this paper, we introduce DynaTCB, a runtime framework designed to balance security and functionality. To enhance security, DynaTCB dynamically adjusts the TCB according to runtime program behavior. To preserve functionality, it logically removes unneeded code from the TCB instead of physically removing it from the enclave, thus avoiding the drawbacks of frequent untrusted interactions. It performs binary-level analysis without requiring source code. Experimental results show that DynaTCB achieves a code reduction of over 95% for the Coreutils suite and more than 80% for real-world applications with 14.2% overhead. Additionally, DynaTCB successfully breaks the gadget chains in SGX and mitigates several Common Vulnerabilities and Exposures (CVEs), affirming its potential to significantly enhance security in SGX environments.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 004533f8-1cb7-4fbb-887a-06c1dadaa272Related papers
- SGXFuzz: Efficiently Synthesizing Nested Structures for SGX Enclave FuzzingTobias Cloosters, Johannes Willbold, Thorsten Holz, Lucas DaviUSENIX Security 2022
- Hacking in Darkness: Return-oriented Programming against Secure EnclavesJae-Hyuk Lee, Jin Soo Jang, Yeongjin Jang, Nohyun Kwak et al.USENIX Security 2017 · 191 citations
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 431 citations
- Towards Memory Safe Enclave Programming with Rust-SGXHuibo Wang, Pei Wang, Yu Ding, Mingshen Sun et al.CCS 2019 · 86 citations
- SGX-Shield: Enabling Address Space Layout Randomization for SGX ProgramsJaebaek Seo, Byoungyoung Lee, Seong-Min Kim, Ming-Wei Shih et al.NDSS 2017 · 227 citations
