USENIX ATC2022顶会
Privbox: Faster System Calls Through Sandboxed Privileged Execution
Dmitry Kuznetsov, Adam Morrison
摘要
System calls are the main method for applications to request services from the operating system, but their invocation incurs considerable overhead, which has been aggravated by mitigation mechanisms for transient execution attacks. Proposed approaches for reducing system call overhead all break the semantic equivalence between system calls and regular function calls (e.g., by making system calls asynchronous), and so their adoption requires rearchitecting applications.
This paper proposes Privbox, a new approach for lightweight system calls that maintains the familiar synchronous, function-like system call model. Privbox allows an application to execute system call-intensive code in a semiprivileged, sandboxed execution mode, called a "privbox". Semi-privileged execution is architecturally similar to the kernel's privileged execution, which enables faster invocation of system calls, but the code is sandboxed to ensure that it cannot use its elevated privileges to compromise the system. We further propose semi-privileged access prevention (SPAP), a simple hardware architectural feature that alleviates much of Privbox's instrumentation overhead.
We implement Privbox based on Linux and LLVM. Our evaluation on x86 (Intel Skylake) hardware shows that Privbox (1) speeds up system call invocation by 2.2×; (2) can increase throughput of I/O-threaded applications by up to 1.7×; and (3) can increase the throughput of real-world workloads such as Redis by up to 7.6% and 11%, without and with SPAP, respectively.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Userspace Bypass: Accelerating Syscall-intensive ApplicationsZhe Zhou, Yanxiang Bi, Junpeng Wan, Yangfan Zhou 等OSDI 2023 · 被引用 18 次
- PANIC: PAN-assisted Intra-process Memory Isolation on ARMJiali Xu, Mengyao Xie, Chenggang Wu, Yinqian Zhang 等CCS 2023 · 被引用 11 次
- ISA-Grid: Architecture of Fine-grained Privilege Control for Instructions and RegistersShulin Fan, Zhichao Hua, Yubin Xia, Haibo Chen 等ISCA 2023 · 被引用 9 次
- HIVE: A Hardware-assisted Isolated Execution Environment for eBPF on AArch64Peihua Zhang, Chenggang Wu, Xiangyu Meng, Yinqian Zhang 等USENIX Security 2024 · 被引用 8 次
- BUDAlloc: Defeating Use-After-Free Bugs by Decoupling Virtual Address Management from KernelJunho Ahn, Jaehyeon Lee, Kanghyuk Lee, Wooseok Gwak 等USENIX Security 2024 · 被引用 6 次
它引用的顶会 Paper5
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp 等USENIX Security 2019 · 被引用 442 次
- An Analysis of Speculative Type Confusion Vulnerabilities in the WildOfek Kirzner, Adam MorrisonUSENIX Security 2021 · 被引用 40 次
- Efficiently Mitigating Transient Execution Attacks using the Unmapped Speculation ContractJonathan Behrens, Anton Cao, Cel Skeggs, Adam Belay 等OSDI 2020 · 被引用 18 次
相关 Paper
- Building Dynamic System Call Sandbox with Partial Order AnalysisQuan Zhang, Chijin Zhou, Yiwen Xu, Zijing Yin 等OOPSLA 2023 · 被引用 5 次
- LatticeBox: A Hardware-Software Co-Designed Framework for Scalable and Low-Latency CompartmentalizationZhanpeng Liu, Chenyang Li, Wende Tan, Yuan Li 等NDSS 2026 · 被引用 1 次
- DataHook: An Efficient and Lightweight System Call Hooking Technique without Instruction ModificationQuan Hong, Jiaqi Li, Wen Zhang, Lidong ZhaiISSTA 2025
- BeeBox: Hardening BPF against Transient Execution AttacksDi Jin, Alexander J. Gaidis, Vasileios P. KemerlisUSENIX Security 2024 · 被引用 10 次
- Pushing Performance Isolation Boundaries into Application with pBoxYigong Hu, Gongqi Huang, Peng HuangSOSP 2023 · 被引用 2 次
