USENIX Security2026Top-tier venue
CoKeMon: Configurable Kernel Monitoring by Decoupling Isolation
Clément Thorens, Shweta Shinde
Abstract
Monolithic OSes such as Linux are susceptible to security vulnerabilities. This has led to a line of research to detect and prevent runtime kernel exploitation, e.g., with kernel integrity measurement, page table monitoring, event logging. Prior works are either purpose-built for one type of monitoring or make invasive changes to the kernel. This motivates the need for a design that can accommodate various monitors on a need basis. As a first step, we identify five key requirements that such a solution must satisfy: selective permissions, non-privileged management, static isolation boundaries, architecturally-supported atomic switching, and device support. It is challenging to satisfy all of the requirements while preserving security. To address this, our insight is to decouple the isolation enforcement from the monitor management, which allows us to use native hardware techniques with ease. We demonstrate the feasibility of such a design on Arm platform by modifying 300 LoC in the firmware and 500 LoC in the Linux kernel. We implement three monitoring use-cases to demonstrate the versatility of COKEMON and report performance overhead ranging from 0% to 13%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d64dc598-ae66-40f6-9bb9-72a69578f799Builds on19
- CURE: A Security Architecture with CUstomizable and Resilient EnclavesRaad Bahmani, Ferdinand Brasser, Ghada Dessouky, Patrick Jauernig et al.USENIX Security 2021 · 150 citations
- Scalable Memory Protection in the PENGLAI EnclaveErhu Feng, Xu Lu, Dong Du, Bicheng Yang et al.OSDI 2021 · 126 citations
- SKEE: A lightweight Secure Kernel-level Execution Environment for ARMAhmed M. Azab, Kirk Swidowski, Rohan Bhutkar, Jia Ma et al.NDSS 2016 · 105 citations
- xMP: Selective Memory Protection for Kernel and User SpaceSergej Proskurin, Marius Momeu, Seyedhamed Ghavamnia, Vasileios P. Kemerlis et al.S&P 2020 · 89 citations
- Logging to the Danger Zone: Race Condition Attacks and Defenses on System Audit FrameworksRiccardo Paccagnella, Kevin Liao, Dave Tian, Adam BatesCCS 2020 · 43 citations
Related papers
- PHMon: A Programmable Hardware Monitor and Its Security Use CasesLeila Delshadtehrani, Sadullah Canakci, Boyou Zhou, Schuyler Eldridge et al.USENIX Security 2020
- DriverJar: Lightweight Device Driver Isolation for ARMHuamao Wu, Yuan Chen, Yajin Zhou, Yifei Wang et al.DAC 2023 · 3 citations
- EKC: A Portable and Extensible Kernel Compartment for De-Privileging Commodity OSJiaqin Yan, Qiujiang Chen, Shuai Zhou, Yuke Peng et al.USENIX Security 2025
- Limitations and Opportunities of Modern Hardware Isolation MechanismsXiangdong Chen, Zhaofeng Li, Tirth Jain, Vikram Narayanan et al.USENIX ATC 2024 · 7 citations
- Tide: An Efficient Kernel-level Isolation Execution Environment on AArch64 via Dynamically Adjusting Output Address SizeShiyang Zhang, Chenggang Wu, Chengxuan Hou, Jinglin Lv et al.CCS 2025
