μSwitch: Fast Kernel Context Isolation with Implicit Context Switches
Dinglan Peng, Congyu Liu, Tapti Palit, Pedro Fonseca, Anjo Vahldiek-Oberwagner, Mona Vij
摘要
Isolating application components is crucial to limit the exposure of sensitive data and code to vulnerabilities in the untrusted components. Process-based isolation is the de facto isolation used in practice, e.g., web browsers. However, it incurs significant performance overhead and is typically infeasible when frequent switches between isolation domains are expected. To address this problem, many intra-process memory isolation techniques have been proposed using novel kernel abstractions, recent CPU extensions (e.g., Intel ® MPK), and software-based fault isolation (e.g., WebAssembly). However, these techniques insufficiently isolate kernel resources, such as file descriptors, or do so by incurring high overheads when resources are accessed. Other work virtualizes the kernel context inside a privileged user space domain, but this is ad-hoc, error-prone, and provides only limited kernel functionalities.
We propose μSWITCH, an efficient kernel context isolation mechanism with memory protection that addresses these limitations. We use a protected structure, shared by the kernel and the user space, for context switching and propose implicit context switching to improve its performance by deferring the kernel resource switch to the next system call. We apply μSWITCH to isolate libraries in the Firefox web browser and an HTTP server, and reduce the overhead of isolation by 32.7% to 98.4% compared with other isolation techniques.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Endokernel: A Thread Safe Monitor for Lightweight Subprocess IsolationFangfei Yang, Bumjin Im, Weijie Huang, Kelly Kaoudis 等USENIX Security 2024 · 被引用 8 次
- Capacity: Cryptographically-Enforced In-Process Capabilities for Modern ARM ArchitecturesKha Dinh Duy, Kyuwon Cho, Taehyun Noh, Hojoon LeeCCS 2023 · 被引用 5 次
- LatticeBox: A Hardware-Software Co-Designed Framework for Scalable and Low-Latency CompartmentalizationZhanpeng Liu, Chenyang Li, Wende Tan, Yuan Li 等NDSS 2026 · 被引用 1 次
- SoK: Software CompartmentalizationHugo Lefeuvre, Nathan Dautenhahn, David Chisnall, Pierre OlivierS&P 2025
- Secpoline: A Scalable Approach to Build Secure In-Process Syscall InterposersRuben Sturm, Anton Schelfhout, Merve Gülmez, Adriaan Jacobs 等USENIX Security 2026
它引用的顶会 Paper29
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler 等USENIX Security 2019 · 被引用 247 次
- Faastlane: Accelerating Function-as-a-Service WorkflowsSwaroop Kotni, Ajay Nayak, Vinod Ganapathy, Arkaprava BasuUSENIX ATC 2021 · 被引用 142 次
- Shreds: Fine-Grained Execution Units with Private MemoryYaohui Chen, Sebassujeen Reymondjohnson, Zhichuang Sun, Long LuS&P 2016 · 被引用 116 次
- Site Isolation: Process Separation for Web Sites within the BrowserCharles Reis, Alexander Moshchuk, Nasko OskovUSENIX Security 2019 · 被引用 105 次
- xMP: Selective Memory Protection for Kernel and User SpaceSergej Proskurin, Marius Momeu, Seyedhamed Ghavamnia, Vasileios P. Kemerlis 等S&P 2020 · 被引用 89 次
相关 Paper
- EPK: Scalable and Efficient Memory Protection KeysJinyu Gu, Hao Li, Wentai Li, Yubin Xia 等USENIX ATC 2022
- PKU Pitfalls: Attacks on PKU-based Memory Isolation SystemsR. Joseph Connor, Tyler McDaniel, Jared M. Smith, Max SchuchardUSENIX Security 2020
- VDom: Fast and Unlimited Virtual Domains on Multiple ArchitecturesZiqi Yuan, Siyu Hong, Rui Chang, Yajin Zhou 等ASPLOS 2023 · 被引用 19 次
- Enforcing Least Privilege Memory Views for Multithreaded ApplicationsTerry Ching-Hsiang Hsu, Kevin J. Hoffman, Patrick Eugster, Mathias PayerCCS 2016 · 被引用 71 次
- Limitations and Opportunities of Modern Hardware Isolation MechanismsXiangdong Chen, Zhaofeng Li, Tirth Jain, Vikram Narayanan 等USENIX ATC 2024 · 被引用 7 次
