Lune

USENIX Security2026顶会

CoKeMon: Configurable Kernel Monitoring by Decoupling Isolation

Clément Thorens, Shweta Shinde

出版方
2026年份

摘要

Monolithic OSes such as Linux are susceptible to security vulnerabilities. This has led to a line of research to detect and prevent runtime kernel exploitation, e.g., with kernel integrity measurement, page table monitoring, event logging. Prior works are either purpose-built for one type of monitoring or make invasive changes to the kernel. This motivates the need for a design that can accommodate various monitors on a need basis. As a first step, we identify five key requirements that such a solution must satisfy: selective permissions, non-privileged management, static isolation boundaries, architecturally-supported atomic switching, and device support. It is challenging to satisfy all of the requirements while preserving security. To address this, our insight is to decouple the isolation enforcement from the monitor management, which allows us to use native hardware techniques with ease. We demonstrate the feasibility of such a design on Arm platform by modifying 300 LoC in the firmware and 500 LoC in the Linux kernel. We implement three monitoring use-cases to demonstrate the versatility of COKEMON and report performance overhead ranging from 0% to 13%.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext d64dc598-ae66-40f6-9bb9-72a69578f799

它引用的顶会 Paper19

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖