Shreds: Fine-Grained Execution Units with Private Memory
Yaohui Chen, Sebassujeen Reymondjohnson, Zhichuang Sun, Long Lu
摘要
Once attackers have injected code into a victim program's address space, or found a memory disclosure vulnerability, all sensitive data and code inside that address space are subject to thefts or manipulation. Unfortunately, this broad type of attack is hard to prevent, even if software developers wish to cooperate, mostly because the conventional memory protection only works at process level and previously proposed in-process memory isolation methods are not practical for wide adoption.
We propose shreds, a set of OS-backed programming primitives that addresses developers' currently unmet needs for finegrained, convenient, and efficient protection of sensitive memory content against in-process adversaries. A shred can be viewed as a flexibly defined segment of a thread execution (hence the name). Each shred is associated with a protected memory pool, which is accessible only to code running in the shred. Unlike previous works, shreds offer in-process private memory without relying on separate page tables, nested paging, or even modified hardware. Plus, shreds provide the essential data flow and control flow guarantees for running sensitive code. We have built the compiler toolchain and the OS module that together enable shreds on Linux. We demonstrated the usage of shreds and evaluated their performance using 5 non-trivial open source software, including OpenSSH and Lighttpd. The results show that shreds are fairly easy to use and incur low runtime overhead (4.67%).
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper45
- Faasm: Lightweight Isolation for Efficient Stateful Serverless ComputingSimon Shillaker, Peter R. PietzuchUSENIX ATC 2020 · 被引用 382 次
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler 等USENIX Security 2019 · 被引用 247 次
- Faastlane: Accelerating Function-as-a-Service WorkflowsSwaroop Kotni, Ajay Nayak, Vinod Ganapathy, Arkaprava BasuUSENIX ATC 2021 · 被引用 142 次
- Designing New Operating Primitives to Improve Fuzzing PerformanceWen Xu, Sanidhya Kashyap, Changwoo Min, Taesoo KimCCS 2017 · 被引用 139 次
- vTZ: Virtualizing ARM TrustZoneZhichao Hua, Jinyu Gu, Yubin Xia, Haibo Chen 等USENIX Security 2017 · 被引用 136 次
相关 Paper
- IMIX: In-Process Memory Isolation EXtensionTommaso Frassetto, Patrick Jauernig, Christopher Liebchen, Ahmad-Reza SadeghiUSENIX Security 2018 · 被引用 77 次
- VDom: Fast and Unlimited Virtual Domains on Multiple ArchitecturesZiqi Yuan, Siyu Hong, Rui Chang, Yajin Zhou 等ASPLOS 2023 · 被引用 19 次
- SEIMI: Efficient and Secure SMAP-Enabled Intra-process Memory IsolationZhe Wang, Chenggang Wu, Mengyao Xie, Yinqian Zhang 等S&P 2020 · 被引用 37 次
- SafeHidden: An Efficient and Secure Information Hiding Technique Using Re-randomizationZhe Wang, Chenggang Wu, Yinqian Zhang, Bowen Tang 等USENIX Security 2019 · 被引用 18 次
- Retrofitting XoM for Stripped Binaries without Embedded Data RelocationChenke Luo, Jiang Ming, Mengfei Xie, Guojun Peng 等NDSS 2025
