Draco: Architectural and Operating System Support for System Call Security
Dimitrios Skarlatos, Qingrong Chen, Jianyan Chen, Tianyin Xu, Josep Torrellas
摘要
System call checking is extensively used to protect the operating system kernel from user attacks. However, existing solutions such as Seccomp execute lengthy rule-based checking programs against system calls and their arguments, leading to substantial execution overhead.
To minimize checking overhead, this paper proposes Draco, a new architecture that caches system call IDs and argument values after they have been checked and validated. System calls are first looked-up in a special cache and, on a hit, skip all checks. We present both a software and a hardware implementation of Draco. The latter introduces a System Call Lookaside Buffer (SLB) to keep recently-validated system calls, and a System Call Target Buffer to preload the SLB in advance. In our evaluation, we find that the average execution time of macro and micro benchmarks with conventional Seccomp checking is 1.14× and 1.25× higher, respectively, than on an insecure baseline that performs no security checks. With our software Draco, the average execution time reduces to 1.10× and 1.18× higher, respectively, than on the insecure baseline. With our hardware Draco, the execution time is within 1% of the insecure baseline.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- IOCost: block IO control for containers in datacentersTejun Heo, Dan Schatzberg, Andrew Newell, Song Liu 等ASPLOS 2022 · 被引用 22 次
- ISA-Grid: Architecture of Fine-grained Privilege Control for Instructions and RegistersShulin Fan, Zhichao Hua, Yubin Xia, Haibo Chen 等ISCA 2023 · 被引用 9 次
- SysXCHG: Refining Privilege with Adaptive System Call FiltersAlexander J. Gaidis, Vaggelis Atlidakis, Vasileios P. KemerlisCCS 2023 · 被引用 9 次
- Empowering WebAssembly with Thin Kernel InterfacesArjun Ramesh, Tianshu Huang, Ben L. Titzer, Anthony RoweEuroSys 2025 · 被引用 7 次
- Perspective: A Principled Framework for Pliable and Secure Speculation in Operating SystemsTae Hoon Kim, David Rudo, Kaiyang Zhao, Zirui Neil Zhao 等ISCA 2024 · 被引用 6 次
它引用的顶会 Paper1
相关 Paper
- Protect the System Call, Protect (Most of) the World with BASTIONChristopher Jelesnianski, Mohannad Ismail, Yeongjin Jang, Dan Williams 等ASPLOS 2023 · 被引用 15 次
- SafeFetch: Practical Double-Fetch Protection with Kernel-Fetch CachingVictor Duta, Mitchel Aloserij, Cristiano GiuffridaUSENIX Security 2024 · 被引用 2 次
- Phoenix: Surviving Unpatched Vulnerabilities via Accurate and Efficient Filtering of Syscall SequencesHugo Kermabon-Bobinnec, Yosr Jarraya, Lingyu Wang, Suryadipta Majumdar 等NDSS 2024
- DPUaudit: DPU-assisted Pull-based Architecture for Near-Zero Cost System AuditingPeng Jiang, Hanlin Jiang, Ruizhe Huang, Hanwen Lei 等HPCA 2025 · 被引用 3 次
- SpecLFB: Eliminating Cache Side Channels in Speculative ExecutionsXiaoyu Cheng, Fei Tong, Hongyu Wang, Zhe Zhou 等USENIX Security 2024 · 被引用 7 次
