Lune

CCS2023顶会

Capacity: Cryptographically-Enforced In-Process Capabilities for Modern ARM Architectures

Kha Dinh Duy, Kyuwon Cho, Taehyun Noh, Hojoon Lee

2023年份
5被引次数
10顶会引用

摘要

In-process compartmentalization and access control have been actively explored to provide in-place and efficient isolation of inprocess security domains. Many works have proposed compartmentalization schemes that leverage hardware features. Newer ARM architectures introduce Pointer Authentication (PA) and Memory Tagging Extension (MTE), adapting the reference validation model for memory safety and runtime exploit mitigation. Despite their potential, these features are underexplored in the context of userspace program compartmentalization. This paper presents Capacity, a novel hardware-assisted intraprocess access control design that embraces capability-based security principles. Capacity coherently incorporates the new hardware security features on ARM, based on the insight that the features already exhibit inherent capability characteristics. It supports the life-cycle protection of the domain's sensitive objects -starting from their import from the file system to their place in memory. With intra-process domains authenticated with unique PA keys, Capacity transforms file descriptors and memory pointers into cryptographically-authenticated references and completely mediates reference usage with its program instrumentation framework and an efficient system call monitor. We evaluate our Capacity-enabled NGINX web server prototype and other common applications in which sensitive resources are isolated into different domains. Our evaluation shows that Capacity incurs a lowperformance overhead of approximately 17% for the single-threaded and 13.54% for the multi-threaded webserver.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper10

问问它们各自怎么用它

它引用的顶会 Paper22

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖