USENIX ATC2023顶会
APRON: Authenticated and Progressive System Image Renovation
Sangho Lee
摘要
The integrity and availability of an operating system are important to securely use a computing device. Conventional schemes focus on how to prevent adversaries from corrupting the operating system or how to detect such corruption. However, how to recover the device from such corruption securely and efficiently is overlooked, resulting in lengthy system downtime with integrity violation and unavailability.
In this paper, we propose APRON, a novel scheme to renovate a corrupt or outdated operating system image securely and progressively. APRON concurrently and selectively repairs any invalid blocks on demand during and after the system boot, effectively minimizing the system downtime needed for a recovery. APRON verifies whether requested blocks are valid in the kernel using a signed Merkle hash tree computed over the valid, up-to-date system image. If they are invalid, it fetches corresponding blocks from a reliable source, verifies them, and replaces the requested blocks with the fetched ones. Once the system boots up, APRON runs a background thread to eventually renovate any other non-requested invalid blocks. Our evaluation shows that APRON has short downtime: it outperforms conventional recovery mechanisms by up to 28×. It runs real-world applications with an average runtime overhead of 9% during the renovation and with negligible overhead (0.01%) once the renovation is completed.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper3
- Dominance as a New Trusted Computing Primitive for the Internet of ThingsMeng Xu, Manuel Huber, Zhichuang Sun, Paul England 等S&P 2019 · 被引用 61 次
- Adaptive Android Kernel Live PatchingYue Chen, Yulong Zhang, Zhi Wang, Liangzhao Xia 等USENIX Security 2017 · 被引用 60 次
- Virtual machine preserving host updates for zero day patching in public cloudMark Russinovich, Naga K. Govindaraju, Melur Raghuraman, David Hepkin 等EuroSys 2021 · 被引用 8 次
相关 Paper
- A Midsummer Night's Tree: Efficient and High Performance Secure SCMSamuel Thomas, Kidus Workneh, Jac McCarty, Joseph Izraelevitz 等ASPLOS 2024 · 被引用 5 次
- A Write-Friendly and Fast-Recovery Scheme for Security Metadata in Non-Volatile MemoriesJianming Huang, Yu HuaHPCA 2021 · 被引用 14 次
- Root Crash Consistency of SGX-style Integrity Trees in Secure Non-Volatile Memory SystemsJianming Huang, Yu HuaHPCA 2023 · 被引用 6 次
- Fast, Transparent Filesystem Microkernel Recovery with AnankeJing Liu, Yifan Dai, Andrea C. Arpaci-Dusseau, Remzi H. Arpaci-DusseauFAST 2025 · 被引用 6 次
- On Scalable Integrity Checking for Secure Cloud DisksQuinn Burke, Ryan Sheatsley, Rachel King, Owen Hines 等FAST 2025 · 被引用 5 次
