CubicleOS: a library OS with software componentisation for practical isolation
Vasily A. Sartakov, Lluís Vilanova, Peter R. Pietzuch
摘要
Library OSs have been proposed to deploy applications isolated inside containers, VMs, or trusted execution environments. They often follow a highly modular design in which third-party components are combined to offer the OS functionality needed by an application, and they are customised at compilation and deployment time to fit application requirements. Yet their monolithic design lacks isolation across components: when applications and OS components contain security-sensitive data (e.g., cryptographic keys or user data), the lack of isolation renders library OSs open to security breaches via malicious or vulnerable third-party components.
We describe CubicleOS, a library OS that isolates components in the system while maintaining the simple, monolithic development approach of library composition. CubicleOS allows isolated components, called cubicles, to share data dynamically with other components. It provides spatial memory isolation at the granularity of function calls by using Intel MPK at user-level to isolate components. At the same time, it supports zero-copy data access across cubicles with feature-rich OS functionality. Our evaluation shows that CubicleOS introduces moderate end-to-end performance overheads in complex applications: 2× for the I/O-intensive NGINX web server with 8 partitions, and 1.7-8× for the SQLite database engine with 7 partitions.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper24
- BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating SystemsAlexander Van't Hof, Jason NiehOSDI 2022 · 被引用 44 次
- FlexOS: towards flexible OS isolationHugo Lefeuvre, Vlad-Andrei Badoiu, Alexander Jung, Stefan Lucian Teodorescu 等ASPLOS 2022 · 被引用 36 次
- You shall not (by)pass!: practical, secure, and fast PKU-based sandboxingAlexios Voulimeneas, Jonas Vinck, Ruben Mechelinck, Stijn VolckaertEuroSys 2022 · 被引用 33 次
- CAP-VMs: Capability-Based Isolation and Sharing in the CloudVasily A. Sartakov, Lluís Vilanova, David M. Eyers, Takahiro Shinagawa 等OSDI 2022 · 被引用 24 次
- LemonNFV: Consolidating Heterogeneous Network Functions at Line SpeedHao Li, Yihan Dang, Guangda Sun, Guyue Liu 等NSDI 2023 · 被引用 21 次
它引用的顶会 Paper4
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler 等USENIX Security 2019 · 被引用 247 次
- BreakApp: Automated, Flexible Application CompartmentalizationNikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn 等NDSS 2018 · 被引用 66 次
- Harmonizing Performance and Isolation in Microkernels with Efficient Intra-kernel Isolation and CommunicationJinyu Gu, Xinyue Wu, Wentai Li, Nian Liu 等USENIX ATC 2020 · 被引用 51 次
- Civet: An Efficient Java Partitioning Framework for Hardware EnclavesChia-Che Tsai, Jeongseok Son, Bhushan Jain, John McAvey 等USENIX Security 2020
相关 Paper
- EKC: A Portable and Extensible Kernel Compartment for De-Privileging Commodity OSJiaqin Yan, Qiujiang Chen, Shuai Zhou, Yuke Peng 等USENIX Security 2025
- Enclosure: language-based restriction of untrusted librariesAdrien Ghosn, Marios Kogias, Mathias Payer, James R. Larus 等ASPLOS 2021 · 被引用 33 次
- Turning Linux into a High-Performance Library OS with FluxKaifu Tian, Youjie Zheng, Yiren Zhang, Yuyang You 等SOSP 2026
- Secure Caches for Compartmentalized SoftwareKerem Arikan, Huaxin Tang, Williams Zhang Cen, Yu David Liu 等USENIX Security 2025
- BULKHEAD: Secure, Scalable, and Efficient Kernel Compartmentalization with PKSYinggang Guo, Zicheng Wang, Weiheng Bai, Qingkai Zeng 等NDSS 2025
