KASLR in the age of MicroVMs
Benjamin Holmes, Jason Waterman, Dan Williams
摘要
Address space layout randomization (ASLR) is a widely used component of computer security aimed at preventing code reuse and/or data-only attacks. Modern kernels utilize kernel ASLR (KASLR) and finer-grained forms, such as functional granular KASLR (FGKASLR), but do so as part of an inefficient bootstrapping process we call bootstrap self-randomization. Meanwhile, under increasing pressure to optimize their boot times, microVM architectures such as AWS Firecracker have resorted to eliminating bootstrapping steps, particularly decompression and relocation from the guest kernel boot process, leaving them without KASLR. In this paper, we present in-monitor KASLR, in which the virtual machine monitor efficiently implements KASLR for the guest kernel by skipping the expensive kernel self-relocation steps. We prototype in-monitor KASLR and FGKASLR in the open-source Firecracker virtual machine monitor demonstrating, on a microVM configured kernel, boot times 22% and 16% faster than bootstrapped KASLR and FGKASLR methods, respectively. We also show the low overhead of in-monitor KASLR, with only 4% (2 ms) increase in boot times on average compared to a kernel without KASLR. We also discuss the implications and future opportunities for in-monitor approaches.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper8
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz 等USENIX Security 2016 · 被引用 500 次
- Fallout: Leaking Data on Meltdown-resistant CPUsClaudio Canella, Daniel Genkin, Lukas Giner, Daniel Gruss 等CCS 2019 · 被引用 289 次
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp 等CCS 2016 · 被引用 278 次
- Firecracker: Lightweight Virtualization for Serverless ApplicationsAlexandru Agache, Marc Brooker, Alexandra Iordache, Anthony Liguori 等NSDI 2020 · 被引用 197 次
- Breaking Kernel Address Space Layout Randomization with Intel TSXYeongjin Jang, Sangho Lee, Taesoo KimCCS 2016 · 被引用 174 次
相关 Paper
- Oreo: Protecting ASLR Against Microarchitectural AttacksShixin Song, Joseph Zhang, Mengjia YanNDSS 2025
- PHMon: A Programmable Hardware Monitor and Its Security Use CasesLeila Delshadtehrani, Sadullah Canakci, Boyou Zhou, Schuyler Eldridge 等USENIX Security 2020
- ASLR on the Line: Practical Cache Attacks on the MMUBen Gras, Kaveh Razavi, Erik Bosman, Herbert Bos 等NDSS 2017 · 被引用 276 次
- The Illusion of Randomness: An Empirical Analysis of Address Space Layout Randomization ImplementationsLorenzo Binosi, Gregorio Barzasi, Michele Carminati, Stefano Zanero 等CCS 2024 · 被引用 4 次
- Sabre: Hardware-Accelerated Snapshot Compression for Serverless MicroVMsNikita Lazarev, Varun Gohil, James Tsai, Andy Anderson 等OSDI 2024 · 被引用 13 次
