USENIX Security2023Top-tier venue
TRust: A Compilation Framework for In-process Isolation to Protect Safe Rust against Untrusted Code
Inyoung Bang, Martin Kayondo, Hyungon Moon, Yunheung Paek
Abstract
Rust was invented to help developers build highly safe systems. It comes with a variety of programming constructs that put emphasis on safety and control of memory layout. Rust enforces strict discipline about a type system and ownership model to enable compile-time checks of all spatial and temporal safety errors. Despite this advantage in security, the restrictions imposed by Rust's type system make it difficult or inefficient to express certain designs or computations. To ease or simplify their programming, developers thus often include untrusted code from unsafe Rust or external libraries written in other languages. Sadly, the programming practices embracing such untrusted code for flexibility or efficiency subvert the strong safety guarantees by safe Rust. This paper presents TRUST, a compilation framework which against untrusted code present in the program, provides trustworthy protection of safe Rust via in-process isolation. Its main strategy is allocating objects in an isolated memory region that is accessible to safe Rust but restricted from being written by the untrusted. To enforce this, TRUST employs software fault isolation and x86 protection keys. It can be applied directly to any Rust code without requiring manual changes. Our experiments reveal that TRUST is effective and efficient, incurring runtime overhead of only 7.55% and memory overhead of 13.30% on average when running 11 widely used crates in Rust.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9d4c4e1b-d0a8-4ea5-8c51-9d76dbdaa716Cited by top-tier papers9
- An Empirical Study of Rust-for-Linux: The Success, Dissatisfaction, and CompromiseHongyu Li, Liwei Guo, Yexuan Yang, Shangguang Wang et al.USENIX ATC 2024 · 29 citations
- RustSan: Retrofitting AddressSanitizer for Efficient Sanitization of RustKyuwon Cho, Jongyoon Kim, Kha Dinh Duy, Hajeong Lim et al.USENIX Security 2024 · 7 citations
- ERASan: Efficient Rust Address SanitizerJiun Min, Dongyeon Yu, Seongyun Jeong, Dokyung Song et al.S&P 2024 · 6 citations
- MetaSafe: Compiling for Protecting Smart Pointer Metadata to Ensure Safe Rust IntegrityMartin Kayondo, Inyoung Bang, Yeongjun Kwak, Hyungon Moon et al.USENIX Security 2024 · 2 citations
- Securing Mixed Rust with Hardware CapabilitiesJason Zhijingcheng Yu, Fangqi Han, Kaustab Choudhury, Trevor E. Carlson et al.CCS 2025 · 1 citation
Builds on12
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler et al.USENIX Security 2019 · 247 citations
- Shreds: Fine-Grained Execution Units with Private MemoryYaohui Chen, Sebassujeen Reymondjohnson, Zhichuang Sun, Long LuS&P 2016 · 116 citations
- TypeSan: Practical Type Confusion DetectionIstván Haller, Yuseok Jeon, Hui Peng, Mathias Payer et al.CCS 2016 · 97 citations
- Towards Memory Safe Enclave Programming with Rust-SGXHuibo Wang, Pei Wang, Yu Ding, Mingshen Sun et al.CCS 2019 · 86 citations
- FreeGuard: A Faster Secure Heap AllocatorSam Silvestro, Hongyu Liu, Corey Crosser, Zhiqiang Lin et al.CCS 2017 · 71 citations
Related papers
- Securing unsafe rust programs with XRustPeiming Liu, Gang Zhao, Jeff HuangICSE 2020 · 28 citations
- How do programmers use unsafe rust?Vytautas Astrauskas, Christoph Matheja, Federico Poli, Peter Müller et al.OOPSLA 2020 · 78 citations
- Is rust used safely by software developers?Ana Nora Evans, Bradford Campbell, Mary Lou SoffaICSE 2020 · 57 citations
- Building Bridges: Safe Interactions with Foreign Languages through OmniglotLeon Schuermann, Jack Toubes, Tyler Potyondy, Pat Pannuto et al.OSDI 2025
- SafeFFI: Efficient Sanitization at the Boundary Between Safe and Unsafe Code in Rust and Mixed-Language ApplicationsOliver Braunsdorf, Tim Lange, Konrad Hohentanner, Julian Horsch et al.USENIX Security 2026
