USENIX Security2026Top-tier venue
Secpoline: A Scalable Approach to Build Secure In-Process Syscall Interposers
Ruben Sturm, Anton Schelfhout, Merve Gülmez, Adriaan Jacobs, Stijn Volckaert
Abstract
In-process system call interposers are increasingly used to extend or monitor application functionality without context-switching or inter-process communication (IPC) overhead. However, when embedded inside untrusted applications, existing solutions face a trade-off: they either enforce no isolation at all, or impose severe restrictions on the monitor's isolated programming environment that are incompatible with complex, real-world use cases. This paper presents Secpoline, a new interposition platform that allows in-process monitors to support arbitrary interposer functionality without compromising isolation. Secpoline achieves this via isolated multi-program loading and a novel meta-monitor design that interposes the monitor itself to emulate a seamless programming environment. In addition, Secpoline implements the first fully self-contained in-process sandbox to harden its own isolation primitive, while preserving fast-path syscall interposition with zero kernel involvement. Our evaluation shows that Secpoline matches the efficiency of state-of-the-art secure in-process interposers while enabling a significantly more expressive programming environment. We specifically demonstrate this by implementing a kernel-module-free version of the Falco intrusion detection engine. We also implement an in-process ProxySQL sidecar, embedded directly into the application process, where Secpoline transparently provides a kernel-bypass communication path to increase throughput by roughly 50%. These results confirm that Secpoline finally delivers on the promise of secure, complex application monitoring at in-process speeds.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e6487f10-0e90-4ceb-a94e-bc84112fffd8Builds on15
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler et al.USENIX Security 2019 · 247 citations
- Firecracker: Lightweight Virtualization for Serverless ApplicationsAlexandru Agache, Marc Brooker, Alexandra Iordache, Anthony Liguori et al.NSDI 2020 · 197 citations
- A Linux in unikernel clothingHsuan-Chi Kuo, Dan Williams, Ricardo Koller, Sibin MohanEuroSys 2020 · 57 citations
- You shall not (by)pass!: practical, secure, and fast PKU-based sandboxingAlexios Voulimeneas, Jonas Vinck, Ruben Mechelinck, Stijn VolckaertEuroSys 2022 · 33 citations
- Unikernel Linux (UKL)Ali Raza, Thomas Unger, Matthew Boyd, Eric B. Munson et al.EuroSys 2023 · 21 citations
Related papers
- Endokernel: A Thread Safe Monitor for Lightweight Subprocess IsolationFangfei Yang, Bumjin Im, Weijie Huang, Kelly Kaoudis et al.USENIX Security 2024 · 8 citations
- Jenny: Securing Syscalls for PKU-based Memory Isolation SystemsDavid Schrammel, Samuel Weiser, Richard Sadek, Stefan MangardUSENIX Security 2022
- PIkit: A New Kernel-Independent Processor-Interconnect RootkitWonJun Song, Hyunwoo Choi, Junhong Kim, Eunsoo Kim et al.USENIX Security 2016 · 13 citations
- SKEE: A lightweight Secure Kernel-level Execution Environment for ARMAhmed M. Azab, Kirk Swidowski, Rohan Bhutkar, Jia Ma et al.NDSS 2016 · 105 citations
- PKU Pitfalls: Attacks on PKU-based Memory Isolation SystemsR. Joseph Connor, Tyler McDaniel, Jared M. Smith, Max SchuchardUSENIX Security 2020
