FlexOS: towards flexible OS isolation
Hugo Lefeuvre, Vlad-Andrei Badoiu, Alexander Jung, Stefan Lucian Teodorescu, Sebastian Rauch, Felipe Huici, Costin Raiciu, Pierre Olivier
摘要
At design time, modern operating systems are locked in a specific safety and isolation strategy that mixes one or more hardware/software protection mechanisms (e.g. user/kernel separation); revisiting these choices after deployment requires a major refactoring effort. This rigid approach shows its limits given the wide variety of modern applications' safety/performance requirements, when new hardware isolation mechanisms are rolled out, or when existing ones break.
We present FlexOS, a novel OS allowing users to easily specialize the safety and isolation strategy of an OS at compilation/deployment time instead of design time. This modular LibOS is composed of finegrained components that can be isolated via a range of hardware protection mechanisms with various data sharing strategies and additional software hardening. The OS ships with an exploration technique helping the user navigate the vast safety/performance design space it unlocks. We implement a prototype of the system and demonstrate, for several applications (Redis/Nginx/SQLite), FlexOS' vast configuration space as well as the efficiency of the exploration technique: we evaluate 80 FlexOS configurations for Redis and show how that space can be probabilistically subset to the 5 safest ones under a given performance budget. We also show that, under equivalent configurations, FlexOS performs similarly or better than existing solutions which use fixed safety configurations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- You shall not (by)pass!: practical, secure, and fast PKU-based sandboxingAlexios Voulimeneas, Jonas Vinck, Ruben Mechelinck, Stijn VolckaertEuroSys 2022 · 被引用 33 次
- Microkernel Goes General: Performance and Compatibility in the HongMeng Production MicrokernelHaibo Chen, Xie Miao, Ning Jia, Nan Wang 等OSDI 2024 · 被引用 13 次
- ISA-Grid: Architecture of Fine-grained Privilege Control for Instructions and RegistersShulin Fan, Zhichao Hua, Yubin Xia, Haibo Chen 等ISCA 2023 · 被引用 9 次
- AlloyStack: A Library Operating System for Serverless Workflow ApplicationsJianing You, Kang Chen, Laiping Zhao, Yiming Li 等EuroSys 2025 · 被引用 7 次
- UIEE: Secure and Efficient User-space Isolated Execution Environment for Embedded TEE SystemsHuaiyu Yan, Zhen Ling, Xuandong Chen, Xinhui Shao 等NDSS 2026 · 被引用 4 次
它引用的顶会 Paper12
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler 等USENIX Security 2019 · 被引用 247 次
- Unikraft: fast, specialized unikernels the easy waySimon Kuenzer, Vlad-Andrei Badoiu, Hugo Lefeuvre, Sharan Santhanam 等EuroSys 2021 · 被引用 116 次
- Using Safety Properties to Generate Vulnerability PatchesZhen Huang, David Lie, Gang Tan, Trent JaegerS&P 2019 · 被引用 91 次
相关 Paper
- CubicleOS: a library OS with software componentisation for practical isolationVasily A. Sartakov, Lluís Vilanova, Peter R. PietzuchASPLOS 2021 · 被引用 38 次
- Fast, Flexible, and Practical Kernel ExtensionsKumar Kartikeya Dwivedi, Rishabh R. Iyer, Sanidhya KashyapSOSP 2024 · 被引用 7 次
- RedLeaf: Isolation and Communication in a Safe Operating SystemVikram Narayanan, Tianjiao Huang, David Detweiler, Dan Appel 等OSDI 2020 · 被引用 86 次
- MELF: Multivariant Executables for a Heterogeneous WorldDominik Töllner, Christian Dietrich, Illia Ostapyshyn, Florian Rommel 等USENIX ATC 2023 · 被引用 8 次
- Turning Linux into a High-Performance Library OS with FluxKaifu Tian, Youjie Zheng, Yiren Zhang, Yuyang You 等SOSP 2026
