HIVE: A Hardware-assisted Isolated Execution Environment for eBPF on AArch64
Peihua Zhang, Chenggang Wu, Xiangyu Meng, Yinqian Zhang, Mingfan Peng, Shiyang Zhang, Bing Hu, Mengyao Xie, Yuanming Lai, Yan Kang, Zhe Wang
摘要
eBPF has become a critical component in Linux. To ensure kernel security, BPF programs are statically verified before being loaded and executed in the kernel. However, the state-ofthe-art eBPF verifier has both security and complexity issues. To this end, we choose to look at BPF programs from a new perspective and regard them as a new type of kernel-mode application, thus an isolation-based rather than a verificationbased approach is needed. In this paper, we propose HIVE, an isolation execution environment for BPF programs on AArch64. To provide the equivalent security guarantees, we systematize the security aims of the eBPF verifier and categorize two types of pointers in eBPF: the inclusive type pointer that points to BPF objects and the exclusive type pointer that points to kernel objects. For the former, HIVE compartmentalizes all BPF memory from the kernel and de-privileges the memory accesses in the BPF programs by leveraging the load/store unprivileged instructions; for the latter, HIVE utilizes the pointer authentication feature to enforce access controls of kernel objects. Evaluation results show that HIVE is not only efficient but also supports complex BPF programs. User-mode Applications System Calls Linux Kernel (EL1) Kernel-mode Applications (BPF)
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Rex: Closing the language-verifier gap with safe and usable kernel extensionsJinghao Jia, Ruowen Qin, Milo Craun, Egor Lukiyanov 等USENIX ATC 2025 · 被引用 11 次
- LatticeBox: A Hardware-Software Co-Designed Framework for Scalable and Low-Latency CompartmentalizationZhanpeng Liu, Chenyang Li, Wende Tan, Yuan Li 等NDSS 2026 · 被引用 1 次
- SoK: Challenges and Paths Toward Memory Safety for eBPFKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson 等S&P 2025
- Approximation Enforced Execution of Untrusted Linux Kernel ExtensionsHao Sun, Zhendong SuUSENIX Security 2025
- KRAKENGUARD: Towards Fine-Grained eBPF IsolationJainil Patel, Lucas Graeff Buhl-Nielsen, Adrien Ghosn, Marios KogiasNSDI 2026
它引用的顶会 Paper18
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez 等USENIX Security 2019 · 被引用 168 次
- XRP: In-Kernel Storage Functions with eBPFYuhong Zhong, Haoyu Li, Yu Jian Wu, Ioannis Zarkadas 等OSDI 2022 · 被引用 100 次
- PACMAN: attacking ARM pointer authentication with speculative executionJoseph Ravichandran, Weon Taek Na, Jay Lang, Mengjia YanISCA 2022 · 被引用 68 次
相关 Paper
- MOAT: Towards Safe BPF Kernel ExtensionHongyi Lu, Shuai Wang, Yechang Wu, Wanning He 等USENIX Security 2024 · 被引用 18 次
- VEP: A Two-stage Verification Toolchain for Full eBPF ProgrammabilityXiwei Wu, Yueyang Feng, Tianyi Huang, Xiaoyang Lu 等NSDI 2025 · 被引用 8 次
- Tide: An Efficient Kernel-level Isolation Execution Environment on AArch64 via Dynamically Adjusting Output Address SizeShiyang Zhang, Chenggang Wu, Chengxuan Hou, Jinglin Lv 等CCS 2025
- Extending Applications Safely and EfficientlyYusheng Zheng, Tong Yu, Yiwei Yang, Yanpeng Hu 等OSDI 2025 · 被引用 7 次
- A Flow-Sensitive Refinement Type System for Verifying eBPF ProgramsAmeer Hamza, Lucas Zavalía, Arie Gurfinkel, Jorge A. Navas 等OOPSLA 2025 · 被引用 1 次
