Jenny: Securing Syscalls for PKU-based Memory Isolation Systems
David Schrammel, Samuel Weiser, Richard Sadek, Stefan Mangard
摘要
Effective syscall filtering is a key component for withstanding the numerous exploitation techniques and privilege escalation attacks we face today. For example, modern browsers use sandboxing techniques with syscall filtering in order to isolate critical code. Cloud computing heavily uses containers, which virtualize the syscall interface. Recently, cloud providers are switching to in-process containers for performance reasons, calling for better isolation primitives. A new isolation primitive that has the potential to fill this gap is called Protection Keys for Userspace (PKU). Unfortunately, prior research highlights severe deficiencies in how PKU-based systems manage syscalls, questioning their security and practicability.
In this work, we comprehensively investigate syscall filtering for PKU-based memory isolation systems. First, we identify new syscall-based attacks that can break a PKU sandbox. Second, we derive syscall filter rules necessary for protecting PKU domains and show efficient ways of enforcing them. Third, we do a comparative study on different syscall interposition techniques with respect to their suitability for PKU, which allows us to design a secure syscall interposition technique that is both fast and flexible.
We design and prototype Jenny-a PKU-based memory isolation system that provides powerful syscall filtering capabilities in userspace. Jenny supports various interposition techniques (e.g., seccomp and ptrace), and allows for domainspecific syscall filtering in a nested way. Furthermore, it handles asynchronous signals securely. Our evaluation shows a minor performance impact of 0-5% for nginx.
PKU needs, being either insecure or slow. We design a new syscall interposition technique that is both secure and fast.
We present Jenny, the first comprehensive PKU-based inprocess isolation system offering dynamic syscall filtering in userspace. Filters can act on the same thread and also be nested across PKU domains. Jenny comes with filter rules for protecting PKU domains and also supports advanced filters such as file system protection. Jenny further supports different syscall interposition techniques. Moreover, Jenny is the first PKU system that supports secure signal handlers. Finally, we introduce novel multi-domain call gates needed to safeguard the PKU policy register on x86-64. Our evaluation shows a minor performance impact of 0-5% for nginx. Contribution. We make the following contributions:
• We identify previously unknown syscall attacks on PKUbased isolation systems.
• We derive syscall filter rules necessary for protecting PKU-based isolation domains.
• We perform a comparative study of various syscall interposition techniques for their applicability with PKU and derive a new technique that is tailored for PKU.
• We design Jenny-the first comprehensive PKU-based isolation system that supports secure (same-thread) userspace syscall filtering, secure (async.) signal handling, and secure multi-domain PKU call gates for x86-64.
• We prototype and evaluate Jenny under different interposition techniques and filter rules, and open-source it 1 . Outline. Section 2 gives some background. Section 3 raises challenges, analyzes the syscall interface and derives filter rules. Section 4 handles syscall interpositioning. Section 5 presents our design, which Section 6 evaluates. Section 7 and 8 discuss limitations and related work, and we conclude in Section 9.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper22
- You shall not (by)pass!: practical, secure, and fast PKU-based sandboxingAlexios Voulimeneas, Jonas Vinck, Ruben Mechelinck, Stijn VolckaertEuroSys 2022 · 被引用 33 次
- Going beyond the Limits of SFI: Flexible and Secure Hardware-Assisted In-Process Isolation with HFIShravan Narayan, Tal Garfinkel, Mohammadkazem Taram, Joey Rudek 等ASPLOS 2023 · 被引用 27 次
- Isolating functions at the hardware limit with virtinesNicholas C. Wanninger, Joshua J. Bowden, Kirtankumar Shetty, Ayush Garg 等EuroSys 2022 · 被引用 17 次
- ISA-Grid: Architecture of Fine-grained Privilege Control for Instructions and RegistersShulin Fan, Zhichao Hua, Yubin Xia, Haibo Chen 等ISCA 2023 · 被引用 9 次
- SysXCHG: Refining Privilege with Adaptive System Call FiltersAlexander J. Gaidis, Vaggelis Atlidakis, Vasileios P. KemerlisCCS 2023 · 被引用 9 次
它引用的顶会 Paper7
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler 等USENIX Security 2019 · 被引用 247 次
- BOOMERANG: Exploiting the Semantic Gap in Trusted Execution EnvironmentsAravind Machiry, Eric Gustafson, Chad Spensky, Christopher Salls 等NDSS 2017 · 被引用 119 次
- Saphire: Sandboxing PHP Applications with Tailored System Call AllowlistsAlexander Bulekov, Rasoul Jahanshahi, Manuel EgeleUSENIX Security 2021 · 被引用 30 次
- PKU Pitfalls: Attacks on PKU-based Memory Isolation SystemsR. Joseph Connor, Tyler McDaniel, Jared M. Smith, Max SchuchardUSENIX Security 2020
相关 Paper
- PANIC: PAN-assisted Intra-process Memory Isolation on ARMJiali Xu, Mengyao Xie, Chenggang Wu, Yinqian Zhang 等CCS 2023 · 被引用 11 次
- SpecMPK: Efficient In-Process Isolation with Speculative and Secure Permission Update InstructionDebpratim Adak, Huiyang Zhou, Eric Rotenberg, Amro AwadHPCA 2025 · 被引用 3 次
- TME-Box: Scalable In-Process Isolation through Intel TME-MK Memory EncryptionMartin Unterguggenberger, Lukas Lamster, David Schrammel, Martin Schwarzl 等NDSS 2025
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris 等NDSS 2016 · 被引用 141 次
- EPF: Evil Packet FilterDi Jin, Vaggelis Atlidakis, Vasileios P. KemerlisUSENIX ATC 2023 · 被引用 14 次
