CoKeMon: Configurable Kernel Monitoring by Decoupling Isolation
Clément Thorens, Shweta Shinde
摘要
Monolithic OSes such as Linux are susceptible to security vulnerabilities. This has led to a line of research to detect and prevent runtime kernel exploitation, e.g., with kernel integrity measurement, page table monitoring, event logging. Prior works are either purpose-built for one type of monitoring or make invasive changes to the kernel. This motivates the need for a design that can accommodate various monitors on a need basis. As a first step, we identify five key requirements that such a solution must satisfy: selective permissions, non-privileged management, static isolation boundaries, architecturally-supported atomic switching, and device support. It is challenging to satisfy all of the requirements while preserving security. To address this, our insight is to decouple the isolation enforcement from the monitor management, which allows us to use native hardware techniques with ease. We demonstrate the feasibility of such a design on Arm platform by modifying 300 LoC in the firmware and 500 LoC in the Linux kernel. We implement three monitoring use-cases to demonstrate the versatility of COKEMON and report performance overhead ranging from 0% to 13%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper19
- CURE: A Security Architecture with CUstomizable and Resilient EnclavesRaad Bahmani, Ferdinand Brasser, Ghada Dessouky, Patrick Jauernig 等USENIX Security 2021 · 被引用 150 次
- Scalable Memory Protection in the PENGLAI EnclaveErhu Feng, Xu Lu, Dong Du, Bicheng Yang 等OSDI 2021 · 被引用 126 次
- SKEE: A lightweight Secure Kernel-level Execution Environment for ARMAhmed M. Azab, Kirk Swidowski, Rohan Bhutkar, Jia Ma 等NDSS 2016 · 被引用 105 次
- xMP: Selective Memory Protection for Kernel and User SpaceSergej Proskurin, Marius Momeu, Seyedhamed Ghavamnia, Vasileios P. Kemerlis 等S&P 2020 · 被引用 89 次
- Logging to the Danger Zone: Race Condition Attacks and Defenses on System Audit FrameworksRiccardo Paccagnella, Kevin Liao, Dave Tian, Adam BatesCCS 2020 · 被引用 43 次
相关 Paper
- PHMon: A Programmable Hardware Monitor and Its Security Use CasesLeila Delshadtehrani, Sadullah Canakci, Boyou Zhou, Schuyler Eldridge 等USENIX Security 2020
- DriverJar: Lightweight Device Driver Isolation for ARMHuamao Wu, Yuan Chen, Yajin Zhou, Yifei Wang 等DAC 2023 · 被引用 3 次
- EKC: A Portable and Extensible Kernel Compartment for De-Privileging Commodity OSJiaqin Yan, Qiujiang Chen, Shuai Zhou, Yuke Peng 等USENIX Security 2025
- Limitations and Opportunities of Modern Hardware Isolation MechanismsXiangdong Chen, Zhaofeng Li, Tirth Jain, Vikram Narayanan 等USENIX ATC 2024 · 被引用 7 次
- Tide: An Efficient Kernel-level Isolation Execution Environment on AArch64 via Dynamically Adjusting Output Address SizeShiyang Zhang, Chenggang Wu, Chengxuan Hou, Jinglin Lv 等CCS 2025
