Going beyond the Limits of SFI: Flexible and Secure Hardware-Assisted In-Process Isolation with HFI
Shravan Narayan, Tal Garfinkel, Mohammadkazem Taram, Joey Rudek, Daniel Moghimi, Evan Johnson, Chris Fallin, Anjo Vahldiek-Oberwagner, Michael LeMay, Ravi Sahita, Dean M. Tullsen, Deian Stefan
摘要
We introduce Hardware-assisted Fault Isolation (HFI), a simple extension to existing processors to support secure, flexible, and efficient in-process isolation. HFI addresses the limitations of existing software-based isolation (SFI) systems including: runtime overheads, limited scalability, vulnerability to Spectre attacks, and limited compatibility with existing code. HFI can seamlessly integrate with current SFI systems (e.g., WebAssembly), or directly sandbox unmodified native binaries. To ease adoption, HFI relies only on incremental changes to the data and control path of existing high-performance processors. We evaluate HFI for x86-64 using the gem5 simulator and compiler-based emulation on a mix of real and synthetic workloads.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Lightweight Fault Isolation: Practical, Efficient, and Secure Software SandboxingZachary YedidiaASPLOS 2024 · 被引用 17 次
- Limitations and Opportunities of Modern Hardware Isolation MechanismsXiangdong Chen, Zhaofeng Li, Tirth Jain, Vikram Narayanan 等USENIX ATC 2024 · 被引用 7 次
- GRANNY: Granular Management of Compute-Intensive Applications in the CloudCarlos Segarra, Simon Shillaker, Guo Li, Eleftheria Mappoura 等NSDI 2025 · 被引用 7 次
- Pegasus: Transparent and Unified Kernel-Bypass Networking for Fast Local and Remote CommunicationDinglan Peng, Congyu Liu, Tapti Palit, Anjo Vahldiek-Oberwagner 等EuroSys 2025 · 被引用 6 次
- SpecMPK: Efficient In-Process Isolation with Speculative and Secure Permission Update InstructionDebpratim Adak, Huiyang Zhou, Eric Rotenberg, Amro AwadHPCA 2025 · 被引用 3 次
它引用的顶会 Paper19
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp 等USENIX Security 2019 · 被引用 442 次
- Faasm: Lightweight Isolation for Efficient Stateful Serverless ComputingSimon Shillaker, Peter R. PietzuchUSENIX ATC 2020 · 被引用 382 次
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler 等USENIX Security 2019 · 被引用 247 次
- Shreds: Fine-Grained Execution Units with Private MemoryYaohui Chen, Sebassujeen Reymondjohnson, Zhichuang Sun, Long LuS&P 2016 · 被引用 116 次
- DOLMA: Securing Speculation with the Principle of Transient Non-ObservabilityKevin Loughlin, Ian Neal, Jiacheng Ma, Elisa Tsai 等USENIX Security 2021 · 被引用 94 次
相关 Paper
- Segue & ColorGuard: Optimizing SFI Performance and Scalability on Modern ArchitecturesShravan Narayan, Tal Garfinkel, Evan Johnson, Zachary Yedidia 等ASPLOS 2025 · 被引用 1 次
- TME-Box: Scalable In-Process Isolation through Intel TME-MK Memory EncryptionMartin Unterguggenberger, Lukas Lamster, David Schrammel, Martin Schwarzl 等NDSS 2025
- PANIC: PAN-assisted Intra-process Memory Isolation on ARMJiali Xu, Mengyao Xie, Chenggang Wu, Yinqian Zhang 等CCS 2023 · 被引用 11 次
- Swivel: Hardening WebAssembly against SpectreShravan Narayan, Craig Disselkoen, Daniel Moghimi, Sunjay Cauligi 等USENIX Security 2021 · 被引用 74 次
- HDFI: Hardware-Assisted Data-Flow IsolationChengyu Song, Hyungon Moon, Monjur Alam, Insu Yun 等S&P 2016 · 被引用 146 次
