Secpoline: A Scalable Approach to Build Secure In-Process Syscall Interposers
Ruben Sturm, Anton Schelfhout, Merve Gülmez, Adriaan Jacobs, Stijn Volckaert
摘要
In-process system call interposers are increasingly used to extend or monitor application functionality without context-switching or inter-process communication (IPC) overhead. However, when embedded inside untrusted applications, existing solutions face a trade-off: they either enforce no isolation at all, or impose severe restrictions on the monitor's isolated programming environment that are incompatible with complex, real-world use cases. This paper presents Secpoline, a new interposition platform that allows in-process monitors to support arbitrary interposer functionality without compromising isolation. Secpoline achieves this via isolated multi-program loading and a novel meta-monitor design that interposes the monitor itself to emulate a seamless programming environment. In addition, Secpoline implements the first fully self-contained in-process sandbox to harden its own isolation primitive, while preserving fast-path syscall interposition with zero kernel involvement. Our evaluation shows that Secpoline matches the efficiency of state-of-the-art secure in-process interposers while enabling a significantly more expressive programming environment. We specifically demonstrate this by implementing a kernel-module-free version of the Falco intrusion detection engine. We also implement an in-process ProxySQL sidecar, embedded directly into the application process, where Secpoline transparently provides a kernel-bypass communication path to increase throughput by roughly 50%. These results confirm that Secpoline finally delivers on the promise of secure, complex application monitoring at in-process speeds.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper15
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler 等USENIX Security 2019 · 被引用 247 次
- Firecracker: Lightweight Virtualization for Serverless ApplicationsAlexandru Agache, Marc Brooker, Alexandra Iordache, Anthony Liguori 等NSDI 2020 · 被引用 197 次
- A Linux in unikernel clothingHsuan-Chi Kuo, Dan Williams, Ricardo Koller, Sibin MohanEuroSys 2020 · 被引用 57 次
- You shall not (by)pass!: practical, secure, and fast PKU-based sandboxingAlexios Voulimeneas, Jonas Vinck, Ruben Mechelinck, Stijn VolckaertEuroSys 2022 · 被引用 33 次
- Unikernel Linux (UKL)Ali Raza, Thomas Unger, Matthew Boyd, Eric B. Munson 等EuroSys 2023 · 被引用 21 次
相关 Paper
- Endokernel: A Thread Safe Monitor for Lightweight Subprocess IsolationFangfei Yang, Bumjin Im, Weijie Huang, Kelly Kaoudis 等USENIX Security 2024 · 被引用 8 次
- Jenny: Securing Syscalls for PKU-based Memory Isolation SystemsDavid Schrammel, Samuel Weiser, Richard Sadek, Stefan MangardUSENIX Security 2022
- PIkit: A New Kernel-Independent Processor-Interconnect RootkitWonJun Song, Hyunwoo Choi, Junhong Kim, Eunsoo Kim 等USENIX Security 2016 · 被引用 13 次
- SKEE: A lightweight Secure Kernel-level Execution Environment for ARMAhmed M. Azab, Kirk Swidowski, Rohan Bhutkar, Jia Ma 等NDSS 2016 · 被引用 105 次
- PKU Pitfalls: Attacks on PKU-based Memory Isolation SystemsR. Joseph Connor, Tyler McDaniel, Jared M. Smith, Max SchuchardUSENIX Security 2020
