DriverJar: Lightweight Device Driver Isolation for ARM
Huamao Wu, Yuan Chen, Yajin Zhou, Yifei Wang, Lubo Zhang
Abstract
Driver-originated vulnerabilities are well-known threats to modern monolithic kernels. However, existing driver isolation solutions either rely on Intel-only or newly-introduced CPU features (e.g., Intel VMFUNC, ARM MTE), or suffer from performance issues, making them unsuitable for existing ARM-based devices. In this work, we leverage a common hardware feature, named hardware watchpoint, to achieve lightweight driver isolation for off-the-shelf ARM devices. Specifically, we utilize watchpoints to prevent the possibly compromised driver from corrupting the rest kernel’s state arbitrarily. We implement a prototype for ARM64 Linux. The security analysis and performance evaluation show the efficiency and practicality of our solution.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 33786dae-a0b4-4312-ae53-89a6e9f2045aCited by top-tier papers1
Ask how each one uses itRelated papers
- Limitations and Opportunities of Modern Hardware Isolation MechanismsXiangdong Chen, Zhaofeng Li, Tirth Jain, Vikram Narayanan et al.USENIX ATC 2024 · 7 citations
- Isolate and Detect the Untrusted Driver with a Virtual BoxYongGang Li, ShunRong Jiang, Yu Bao, Pengpeng Chen et al.CCS 2024
- SKEE: A lightweight Secure Kernel-level Execution Environment for ARMAhmed M. Azab, Kirk Swidowski, Rohan Bhutkar, Jia Ma et al.NDSS 2016 · 105 citations
- Camouflage: Hardware-assisted CFI for the ARM Linux kernelRémi Denis-Courmont, Hans Liljestrand, Carlos Chinea Perez, Jan-Erik EkbergDAC 2020 · 18 citations
- CoKeMon: Configurable Kernel Monitoring by Decoupling IsolationClément Thorens, Shweta ShindeUSENIX Security 2026
