Kite: lightweight critical service domains
A. K. M. Fazla Mehrab, Ruslan Nikolaev, Binoy Ravindran
摘要
Converged multi-level secure (MLS) systems, such as Qubes OS or SecureView, heavily rely on virtualization and service virtual machines (VMs). Traditionally, driver domains -isolated VMs that run device drivers -and daemon VMs use full-blown general-purpose OSs. It seems that specialized lightweight OSs, known as unikernels, would be a better fit for those. Surprisingly, to this day, driver domains can only be built from Linux. We discuss how unikernels can be beneficial in this context -they improve security and isolation, reduce memory overheads, and simplify software configuration and deployment. We specifically propose to use unikernels that borrow device drivers from existing general-purpose OSs.
We present Kite which implements network and storage unikernel-based VMs and serve two essential classes of devices. We compare our approach against Linux using a number of typical micro-and macrobenchmarks used for networking and storage. Our approach achieves performance similar to that of Linux. However, we demonstrate that the number of system calls and ROP gadgets can be greatly reduced with our approach compared to Linux. We also demonstrate that our approach has resilience to an array of CVEs (e.g., CVE-2021-35039, CVE-2016-4963, and CVE-2013-2072), smaller image size, and improved startup time. Finally, unikernelizing is doable for the remaining (non-driver) service VMs as evidenced by our unikernelized DHCP server.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- Panoply: Low-TCB Linux Applications With SGX EnclavesShweta Shinde, Dat Le Tien, Shruti Tople, Prateek SaxenaNDSS 2017 · 被引用 274 次
- A Linux in unikernel clothingHsuan-Chi Kuo, Dan Williams, Ricardo Koller, Sibin MohanEuroSys 2020 · 被引用 57 次
- Deconstructing XenLe Shi, Yuming Wu, Yubin Xia, Nathan Dautenhahn 等NDSS 2017 · 被引用 54 次
- Adelie: continuous address space layout re-randomization for Linux driversRuslan Nikolaev, Hassan Nadeem, Cathlyn Stone, Binoy RavindranASPLOS 2022 · 被引用 20 次
- Temporal System Call Specialization for Attack Surface ReductionSeyedhamed Ghavamnia, Tapti Palit, Shachee Mishra, Michalis PolychronakisUSENIX Security 2020
相关 Paper
- CofferOS: Hardening OS-level Virtualization with RustMinkyu Jung, Chanshin Kwak, Junho Ahn, Sunho Park 等EuroSys 2026
- A Hardware-Software Co-Design for Efficient Secure ContainersJiacheng Shi, Yang Yu, Jinyu Gu, Yubin XiaEuroSys 2025
- Veil: A Protected Services Framework for Confidential Virtual MachinesAdil Ahmad, Botong Ou, Congyu Liu, Xiaokuan Zhang 等ASPLOS 2023 · 被引用 12 次
- Unikraft: fast, specialized unikernels the easy waySimon Kuenzer, Vlad-Andrei Badoiu, Hugo Lefeuvre, Sharan Santhanam 等EuroSys 2021 · 被引用 116 次
- Nephele: Extending Virtualization Environments for Cloning Unikernel-based VMsCostin Lupu, Andrei Albisoru, Radu Nichita, Doru-Florin Blânzeanu 等EuroSys 2023 · 被引用 10 次
