PTStore: Lightweight Architectural Support for Page Table Isolation
Wende Tan, Yangyu Chen, Yuan Li, Ying Liu, Jianping Wu, Yu Ding, Chao Zhang
摘要
Page tables are critical data structures in kernels, serving as the trust base of most mitigation solutions. Their integrity is thus crucial but is often taken for granted. Existing page table protection solutions usually provide insufficient security guarantees, require heavy hardware, or introduce high overheads. In this paper, we present a novel lightweight hardware-software co-design solution, PTStore, consisting of a secure region storing page tables and tokens verifying page table pointers. Evaluation results on FPGA-based prototypes show that PTStore only introduces <0.92% hardware overheads and <0.86% performance overheads, but provides strong security guarantees, showing that PTStore is efficient and effective.
• We propose a novel lightweight hardware-software co-design solution PTStore, consisting of a secure region and a novel token mechanism, to protect page tables.
• We build an FPGA-based prototype of PTStore on RISC-V.
• We conduct a thorough performance and security evaluation, showing that PTStore is lightweight, practical, and efficient, as well as effective against various page table attacks.
RISC-V and many other ISAs provide PMP support, which enables M-mode code to configure permissions of physical memory regions for S-mode code and data [17]. For example, M-mode code can mask some physical memory ranges so that kernels in S-mode are not permitted to access them.
Page tables are critical data structures in kernels as they store address mappings and access permissions of VM pages. A system can get compromised if even only one bit of its page tables gets flipped [18]. However, page tables are vulnerable to both hardware [18] and software [4] vulnerabilities. Once memory-corruption vulnerabilities exist, attackers can utilize the following techniques to compromise the system (including kernels and even deployed mitigations), which is similar to code corruption, injection, and reuse attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper10
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic 等EuroSys 2020 · 被引用 381 次
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez 等USENIX Security 2019 · 被引用 168 次
- Scalable Memory Protection in the PENGLAI EnclaveErhu Feng, Xu Lu, Dong Du, Bicheng Yang 等OSDI 2021 · 被引用 126 次
- SKEE: A lightweight Secure Kernel-level Execution Environment for ARMAhmed M. Azab, Kirk Swidowski, Rohan Bhutkar, Jia Ma 等NDSS 2016 · 被引用 105 次
- xMP: Selective Memory Protection for Kernel and User SpaceSergej Proskurin, Marius Momeu, Seyedhamed Ghavamnia, Vasileios P. Kemerlis 等S&P 2020 · 被引用 89 次
相关 Paper
- PT-Rand: Practical Mitigation of Data-only Attacks against Page TablesLucas Davi, David Gens, Christopher Liebchen, Ahmad-Reza SadeghiNDSS 2017 · 被引用 73 次
- ZeRØ: Zero-Overhead Resilient Operation Under Pointer Integrity AttacksMohamed Tarek Ibn Ziad, Miguel A. Arroyo, Evgeny Manzhosov, Simha SethumadhavanISCA 2021 · 被引用 17 次
- Accelerating Extra Dimensional Page Walks for Confidential ComputingDong Du, Bicheng Yang, Yubin Xia, Haibo ChenMICRO 2023 · 被引用 7 次
- DMGuard: Safeguarding Kernels from Physical-Page Use-After-Free VulnerabilitiesJuhee Kim, Jaeyoung Chung, Dae R. Jeong, Byoungyoung LeeUSENIX Security 2026
- Trust-V: Toward Secure and Reliable Storage for Trusted Execution EnvironmentsSeung-Kyun Han, Jiyeon Yang, Jinsoo JangASPLOS 2026
