scieee Science in your language
[en] (orig)

Techniques to Protect Confidentiality and Integrity of Persistent and In-Memory Data

Abstract

Today computers store and analyze valuable and sensitive data. As a result we need to protect this data against confidentiality and integrity violations that can result in the illicit release, loss, or modification of a user’s and an organization’s sensitive data such as personal media content or client records. Existing techniques protecting confidentiality and integrity lack either efficiency or are vulnerable to malicious attacks. In this thesis we suggest techniques, Guardat and ERIM, to efficiently and robustly protect persistent and in-memory data. To protect the confidentiality and integrity of persistent data, clients specify per-file policies to Guardat declaratively, concisely and separately from code. Guardat enforces policies by mediating I/O in the storage layer. In contrast to prior techniques, we protect against accidental or malicious circumvention of higher software layers. We present the design and prototype implementation, and demonstrate that Guardat efficiently enforces example policies in a web server. To protect the confidentiality and integrity of in-memory data, ERIM isolates sensitive data using Intel Memory Protection Keys (MPK), a recent x86 extension to partition the address space. However, MPK does not protect against malicious attacks by itself. We prevent malicious attacks by combining MPK with call gates to trusted entry points and ahead-of-time binary inspection. In contrast to existing techniques, ERIM efficiently protects frequently-used session keys of web servers, an in-memory reference monitor’s private state, and managed runtimes from native libraries. These use cases result in high switch rates of the order of 10 5 –10 6 switches/s. Our experiments demonstrate less then 1% runtime overhead per 100,000 switches/s, thus outperforming existing techniques.

Read accessible full text

Techniques to Protect Confidentiality and Integrity of Persistent and In-Memory Data

Author: Vahldiek-Oberwagner, Anjo Lucas
Publisher: Saarländische Universitäts- und Landesbibliothek
Year: 2018
DOI: http://dx.doi.org/10.22028/D291-27731
Source: https://publikationen.sulb.uni-saarland.de/bitstream/20.500.11880/27354/1/thesis.pdf
Techniques o P o ec
Con iden iali y and In eg i y o
Pe sis en and In-Memo y Da a
A disse a ion submi ed owa ds he deg ee
Doc o o Enginee ing
o he Facul y o Ma hema ics and Compu e Science
o Saa land Uni e si y
by
Anjo Lucas Vahldiek-Obe wagne
Saa b ücken
Oc obe , 2018
Da e o Colloquium: Feb ua y 5 h, 2019
Dean o Facul y: P o . D . Sebas ian Hack
Chai o he Commi ee: P o . D . Ge Smolka
Repo e s
Fi s Re iewe : P o . Pe e D uschel, Ph.D.
Second Re iewe : Deepak Ga g, Ph.D.
Thi d Re iewe : S e an Sa oiu, Ph.D.
Academic Assis an : Engel Le aucheux, Ph.D.
II
III
Abs ac
Today compu e s s o e and analyze aluable and sensi i e da a. As a esul we need
o p o ec his da a agains con iden iali y and in eg i y iola ions ha can esul
in he illici elease, loss, o modi ica ion o a use ’s and an o ganiza ion’s sensi i e
da a such as pe sonal media con en o clien eco ds. Exis ing echniques p o ec ing
con iden iali y and in eg i y lack ei he e iciency o a e ulne able o malicious
a acks. In his hesis we sugges echniques, Gua da and ERIM, o e icien ly and
obus ly p o ec pe sis en and in-memo y da a.
To p o ec he con iden iali y and in eg i y o pe sis en da a, clien s speci y
pe - ile
policies o Gua da decla a i ely, concisely and sepa a ely om code. Gua da
en o ces policies by media ing I/O in he s o age laye . In con as o p io echniques,
we p o ec agains acciden al o malicious ci cum en ion o highe so wa e laye s.
We p esen he design and p o o ype implemen a ion, and demons a e ha Gua da
e icien ly en o ces example policies in a web se e .
To p o ec he con iden iali y and in eg i y o in-memo y da a, ERIM isola es
sensi i e da a using In el Memo y P o ec ion Keys (MPK), a ecen x86 ex ension
o pa i ion he add ess space. Howe e , MPK does no p o ec agains malicious
a acks by i sel . We p e en malicious a acks by combining MPK wi h call ga es
o us ed en y poin s and ahead-o - ime bina y inspec ion. In con as o exis ing
echniques, ERIM e icien ly p o ec s equen ly-used session keys o web se e s,
an in-memo y e e ence moni o ’s p i a e s a e, and managed un imes om na i e
lib a ies. These use cases esul in high swi ch a es o he o de o 10
5
–10
6
swi ches/s.
Ou expe imen s demons a e less hen 1% un ime o e head pe 100,000 swi ches/s,
hus ou pe o ming exis ing echniques.
IV
Ku zda s ellung
Compu e speiche n und analysie en we olle und sensi i e Da en. Das ha zu Folge,
dass wi diese Da en gegen Ve aulichkei s- und In eg i ä s e le zungen schü zen
müssen. Ande n alls d oh die une laub e F eigabe, de Ve lus ode die Modi ika ion
de Da en. Exis ie ende Me hoden schü zen die Ve aulichkei und In eg i ä
unzu eichend, da sie ine izien und an ällig ü mu willige Ang i e sind. In diese
Dok o a bei s ellen wi zwei Me hoden, Gua da und ERIM, o , die pe sis en e
Da en und Da en im A bei sspeiche e izien und wide s ands ähig beschü zen.
Um die Ve aulichkei und In eg i ä pe sis en e Da en zu schü zen, e knüp en
Nu ze ü jede Da ei Rich linien in Gua da . Gua da übe p ü diese Rich linien ü
jeden Zug i und se z diese im Speiche medium du ch. Im Gegensa z zu exis ie en-
den Me hoden, beschü z Gua da o mu willigem Umgehen. Wi besch eiben die
Me hode, eine Implemen ie ung und e aluie en die E izienz on Beispiel ich linien.
Um die Ve aulichkei und In eg i ä on Da en im A bei sspeiche zu schü zen,
isolie ERIM sensi i e Da en mi Hil e on In el Memo y P o ec ion Keys (MPK),
eine neue x86 E wei e ung, um den A bei sspeiche au zu eilen. Da MPK alle dings
nich gegen mu willige Ang i e schü z , e hinde ERIM diese, indem es MPK mi
wide s ands ähigen Wechseln de Speiche be eiche und eine Binä codeübe p ü ung
kombinie . Im Gegensa z zu exis ie enden Me hoden, beschü z ERIM e izien
häu ig genu z e Si zungsschlüssel, Zus ands a iablen eines Re e enzmoni o s und
e wal e e Lau zei umgebungen on na i en Biblio heken. Unse e Expe imen e
zeigen, dass wenige als 1% Lau zei meh au wand je 100.000 Wechselope a ionen p o
Sekunde no wendig sind.
V

Publica ions
Pa s o his hesis ha e appea ed in he ollowing publica ions.
•
“Gua da : En o cing da a policies a he s o age laye ”. Anjo Vahldiek-
Obe wagne , Eslam Elnike y, Aas ha Meh a, Deepak Ga g, Pe e D uschel,
Ansley Pos , Rod igo Rod igues, Johannes Geh ke. In P oceedings o he
Eu opean Con e ence on Compu e Sys ems (Eu oSys), 2015.
•
“ERIM: Secu e and E icien In-p ocess Isola ion”, Anjo Vahldiek-Obe wagne ,
Eslam Elnike y, Nuno O. Dua e, Deepak Ga g, Pe e D uschel. Unde e iew
and echnical epo (a Xi :1801.06822), 2018.
Addi ional publica ions no included in his hesis.
•
“P o ec ing Da a In eg i y wi h S o age Leases”, Anjo Vahldiek, Eslam Elnike y,
Ansley Pos , Pe e D uschel, Rod igo Rod igues. MPI-SWS Technical Repo
2011-008.
•
“Tho h: Comp ehensi e Policy Compliance in Da a Re ie al Sys ems”, Eslam
Elnike y, Aas ha Meh a, Anjo Vahldiek-Obe wagne , Deepak Ga g, Pe e
D uschel. In P oceedings o he USENIX Secu i y Symposium, 2016.
•
“Ligh -Weigh Con ex s: An OS Abs ac ion o Sa e y and Pe o mance”,
James Li on, Anjo Vahldiek-Obe wagne , Eslam Elnike y, Deepak Ga g, Bobby
Bha acha jee, Pe e D uschel. In P oceedings o he USENIX Symposium on
Ope a ing Sys ems Design and Implemen a ion (OSDI), 2016.
VI
•
“Pesos: Policy Enhanced Secu e Objec S o e”, Robe K ahn, Bohdan T ach,
Anjo Vahldiek-Obe wagne , Thomas Knau h, P amod Bha o ia, Ch is o Fe ze .
In P oceedings o he Eu opean Con e ence on Compu e Sys ems (Eu oSys),
2018.
VII
Fynn, Julius, Timon and Ke s in.
VIII
Acknowledgmen s
I would like o ex end my hanks o many people. They so gene ously con ibu ed
o he wo k p esen ed in his hesis and helped me du ing he ups and downs o
g adua e li e.
Fi s ly, I would like o exp ess my since e g a i ude o my ad ise s Pe e D uschel
and Deepak Ga g o hei con inuous suppo . Thei guidance helped me in esea ch
and w i ing o his hesis. I’m e y g a e ul o hem o gi ing me he ime o aise
my amily and be wi h my child en.
I would like o hank he es o my hesis commi ee: Paul F ancis, and S e an
Sa oiu, o hei insigh ul commen s and encou agemen , bu also o he ha d
ques ions which helped me o u he imp o e my esea ch om a ious pe spec i es.
I ha e been e y o una e o collabo a e wi h an as ic ellow PhD s uden s,
Eslam Elnike y and Aas ha Me ha. Wi h hem, he coun less and i ing deadlines
u ned in o ad en u e ips. I canno imagine going h ough g adua e li e wi hou
hei iendship and suppo .
Besides Eslam and Aas ha, I had he g ea pleasu e o collabo a e wi h Bobby
Bha acha jee, Nuno Dua e, Johannes Geh ke, James Li on, Rod igo Rod igues,
and Ansley Pos .
Fu he mo e, I would like o hank ellow s uden s and pos docs a MPI-SWS
o c ea ing a g ea place o wo k, in pa icula A pan, Bimal, Bilal, Cheng, Ekin,
Ezgi, Felipe, Filip, Geo g, Jan-Oli e , James, Juhi, Manoha , Na acha, Nancy, Nuno,
Oana, Paa ijaa , Ped o, P amod, Reinha d, Sco , and Vik o .
IX
Lis o Figu es
2.1 Re e ence moni o implemen a ion scena ios . . . . . . . . . . . . . . 8
3.1 Gua da implemen a ion in a SAN se e . . . . . . . . . . . . . . . . 40
3.2 Absolu e Gua da la ency o e head . . . . . . . . . . . . . . . . . . . 47
3.3 La ency wi h an SSD, ela i e o iSCSI . . . . . . . . . . . . . . . . . 48
3.4 Absolu e la ency wi h SSD . . . . . . . . . . . . . . . . . . . . . . . . 49
3.5 Absolu e la ency wi h HDD . . . . . . . . . . . . . . . . . . . . . . . 49
3.6 SSDI/O h oughpu ........................... 50
3.7 FS benchma ks ead and w i e ( /w) pe o mance . . . . . . . . . . . 53
3.8 Web se e h oughpu . . . . . . . . . . . . . . . . . . . . . . . . . . 55
3.9 La ency wi h MAL, olun a y and no logging . . . . . . . . . . . . . 57
4.1
SPEC CPU o e head o CPI/CPS wi h ERIM and an emu-
la ion o WRPKRU (EMUL-CPI/CPS), ela i e o no p o ec ion . . . 90
4.2
SPEC CPU o e head o CPI/CPS and ERIM-CPI/CPS,
ela i e o no p o ec ion. . . . . . . . . . . . . . . . . . . . . . . . . . 95
4.3 Nginx h oughpu wi h one wo ke wi h and wi hou ERIM . . . . . 98
4.4 Nginx h oughpu wi h one wo ke wi h emula ed ERIM and lwCs . . 102
5.1 S eps owa ds an isola ed c yp og aphic lib a y in se e applica ions 116
XVI

CHAPTER 1
In oduc ion
Today compu e s assis people in mos daily ac i i ies such as social in e ac-
ions, lea ning, and in o ma ion sha ing. People en us compu e sys ems wi h
hei aluable da a, e.g., pe sonal media con en , inancial and heal h eco ds, and
c yp og aphic keys. Compu e sys ems ough o p o ec he con iden iali y and
in eg i y o such da a. Con iden iali y gua an ees ha only au ho ized eads o he
da a succeed. In eg i y p e en s unau ho ized upda es o he da a.
Viola ing he con iden iali y and in eg i y o sensi i e da a can esul in i s
leak, loss o modi ica ion. As a esul clien s and o ganiza ions may ace he loss o
highly sen imen al da a and epu a ional o inancial loss. Common causes o da a
con iden iali y and in eg i y iola ions [
15
] include so wa e bugs, secu i y ulne -
abili ies, miscon igu a ion and ope a o e o . Fi s , a bug, e.g., in an applica ion
may o e w i e exis ing iles, iola ing in eg i y. Second, secu i y ulne abili ies in
online se ices may be used by malicious a acke s o ex ac sensi i e da a such as
c yp og aphic keys, iola ing con iden iali y. Thi d, miscon igu a ions may lead o
acciden al da a eads, iola ing con iden iali y. Fou h, an adminis a i e ope a o
o a sys em may acciden ally dele e da a om he sys em, iola ing in eg i y.
To p e en hese iola ions, many echniques o p o ec da a con iden iali y
and in eg i y ha e been p oposed. Model checking, language-based s a ic analysis,
es ing and e e ence moni o s a e b oad classes o such echniques. Model checking
ensu es ha an applica ion ollows a gi en speci ica ion, and hus p o ides he
1
s onges gua an ees compa ed o he emaining gua an ees. Howe e , model checking
o e e yday so wa e (e.g., ope a ing sys ems o web b owse s) is complex and
consequen ly di icul and expensi e, which limi s he use o model checking o
speci ic componen s in high- isk applica ions. Language-based s a ic analysis en o ces
speci ic p og am in a ian s o e sou ce code and ma ks in a ian iola ions such
as bugs and ulne abili ies du ing de elopmen . Due o he app oxima ion o
un ime alues, analysis ools su e in p ac ice om high alse posi i es a es. In
addi ion, limi ed suppo o mul i-language so wa e sys ems hinde s hei b oad
adop ion [
104
]. Tes ing, on he o he hand, p o ides a easonable and bes -e o
co e age o iola ions o e a subse o applica ion inpu s. Al hough widely used,
es ing-based app oaches do no p o ide o mal gua an ees, since es ing e e y
possible inpu is usually un easible, especially when conside ing malicious a acks.
Thus, none o hese echniques p o ides he abili y o en o ce con iden iali y and
in eg i y sys ema ically ac oss applica ions and independen o he applica ion
implemen a ion.
In con as , e e ence moni o s [
6
] en o ce con iden iali y and in eg i y o da a by
obse ing applica ions a un ime, media ing ele an e en s (such as I/O o memo y
accesses) and denying accesses which iola e con iden iali y o in eg i y. T ea ing
he applica ion as a black box allows e e ence moni o s o en o ce con iden iali y
and in eg i y independen o he applica ion implemen a ion and applica ion size,
and sys ema ically ac oss applica ions. This allows adop ion ac oss a wide ange o
use cases including legacy applica ions wi h no access o sou ce code. Compa ed
o model checking o s a ic analysis, which p o e co ec ness o an applica ion,
e e ence moni o s educe he p oo o co ec ness o a smalle and simple piece o
code, namely he e e ence moni o . In con as o he o he echniques, e e ence
moni o s induce un ime o e head on he p oduc ion sys ems o which hey a e
applied. Reducing his o e head is an impo an design conside a ion.
2
Re e ence moni o s ha e been applied o a ious use cases. When p o ec ing da a
con iden iali y and in eg i y, we di e en ia e be ween p o ec ing in- ansi ,pe sis en ,
o in-memo y da a.In- ansi da a is ypically p o ec ed using c yp og aphic me hods
which enc yp he con en s p o iding con iden iali y, and sign he con en s p o iding
in eg i y. Fo secu e communica ion oday’s compu e sys ems ely on he SSL/TLS
s anda d wi h eadily a ailable implemen a ions in se e al c yp og aphic lib a ies
such as OpenSSL [
96
]. Howe e , o bo h, pe sis en and in-memo y da a, exis ing
echniques do no e icien ly and comp ehensi ely p o ec da a con iden iali y and
in eg i y [134, 45, 110, 124, 48, 3, 74, 59, 29, 68, 75, 113, 58, 38, 29].
To p o ec he con iden iali y and in eg i y o pe sis en da a, exis ing moni o ing
echniques [
48
,
134
,
45
,
118
,
139
,
19
,
74
,
5
,
124
,
110
] media e applica ion I/O by in
a lib a y, ile sys em, ope a ing sys em, hype iso , o in he s o age laye . Howe e ,
media ion in a laye o he han he s o age laye can be easily bypassed, and none
o he s o age laye echniques suppo gene al con iden iali y and in eg i y policies.
Hence, a s ong and gene al policy en o cemen echnique o pe sis en da a is
cu en ly missing.
To p o ec he con iden iali y and in eg i y o in-memo y da a om accesses by
an un us ed applica ion, p io wo k elies on memo y isola ion h ough language and
un ime [
38
,
72
,
129
,
143
,
68
], p ocess-based [
74
,
59
,
29
,
20
], o andomiza ion-based
echniques [
113
,
58
]. Fi s , language and un ime echniques isola e by inse ing
checks in o he applica ion bina y o p o ec agains a bi a y da a accesses. Al hough
obus agains malicious a acks, hese echniques su e om un ime o e heads
o pe o m he checks. Second, p ocess-based isola ion spli s he execu ion o an
applica ion in o sepa a e ha dwa e-p o ec ed p ocesses. Simila o language and
un ime isola ion, p ocess-based isola ion is obus agains malicious a acks. The
e iciency depends on he cos o con ex swi ches be ween applica ion p ocesses,
which is usually high. Thi d, andomiza ion-based isola ion uses he huge add ess
space o hide sensi i e da a a a andom loca ion. While andomiza ion-based
3
echniques a e e icien (no checks o high swi ch cos s), malicious a acke s can
ind he sec e loca ion and b eak gua an ees [
113
,
60
,
39
,
49
,
94
]. No exis ing
echnique e icien ly isola es memo y wi h low un ime o e head, and o e s s ong
p o ec ion agains malicious a acke s. As a esul , no exis ing isola ion echnique is
su icien o se e al impo an use cases such as p o ec ing c yp og aphic keys o
na i e lib a ies in managed un imes.
Con ibu ions:
This disse a ion con ibu es Gua da , which e icien ly en o ces ex-
p essi e con iden iali y and in eg i y policies a he s o age laye p o ec ing pe sis en
da a, and ERIM, which s ongly and e icien ly isola es in-memo y da a.
Gua da :
In con as o p e ious echniques [
48
,
134
,
45
,
118
,
139
,
19
,
74
] ha
in e cep a he applica ion o a sys em so wa e laye , Gua da p o ec s he con-
iden iali y and in eg i y o pe sis en da a a he s o age laye . Thus, Gua da
minimizes he size and a ack su ace o he us ed compu ing base (TCB) elied
upon o en o cemen .
P o ec ing a he s o age laye limi s a ailable access in o ma ion o block
add esses. As a esul , exis ing s o age laye echniques echniques [
5
,
124
,
110
] do
no en o ce gene ic con iden iali y and in eg i y policies. To o e come he lack o
clien in o ma ion such as ile names and access c eden ials, clien s communica e wi h
Gua da h ough secu e channels, unneling h ough un us ed sys em laye s like he
ope a ing sys em. Clien s use his communica ion o send addi ional in o ma ion
such as ile names o access c eden ials. Using his in o ma ion, Gua da en o ces
con iden iali y and in eg i y o e e y da a access while elying only on i s own
en o cemen logic.
Wi h Gua da , con iden iali y and in eg i y equi emen s a e speci ied as pe - ile
policies by use s, de elope s, o adminis a o s. Policies speci y he condi ions unde
which a ile may be ead, upda ed, o ha e i s policy changed. These condi ions,
w i en in a decla a i e language, may depend on clien au hen ica ion, he ini ial
4
and inal s a es o he ile (size and con en ) in an upda e ansac ion, o signed
s a emen s by ex e nal us ed componen s (ce i ying, o ins ance, he cu en
wall-clock ime). Gua da s o es he policy as pa o i s own me ada a and ensu es
ha each access o he ile complies wi h he policy.
Fo example, use s can ely on Gua da o mi iga e se ious h ea s: To p e en
he inse ion o malicious code in execu ables, a policy can p o ec execu able iles
by allowing only upda es signed by a us ed pa y; o p e en sys em logs om
co up ion and ampe ing, a policy can p o ec log iles by making hem append-only;
o p e en he illici elease o a use ’s p i a e da a, a policy can p o ec he use ’s
da a by equi ing an au hen ica ed secu e session o ead da a; o p e en a bi a y
ile accesses and allow audi ing o accesses, a policy can p o ec iles by equi ing a
manda o y log en y be o e accessing a ile.
We e alua e he e iciency o Gua da using he policy examples desc ibed
abo e. We show ha Gua da en o ces con iden iali y and in eg i y policies wi h low
o e head. When p o ec ing a web se e ’s con en om accesses by unau ho ized
use s, and bina ies om unau ho ized upda es, he h oughpu o e head is less han
1% compa ed o no p o ec ion.
ERIM:
ERIM is a amewo k o s ong, e icien isola ion o in-memo y da a. I
allows pa i ioning an applica ion in o a us ed and an un us ed componen wi hin
a single add ess space. Fo his, ERIM elies on Memo y P o ec ion Keys (MPK) [
64
],
a ecen x86 ex ension o pa i ion he add ess space in o up o 16 disjoin memo y
domains. Wi h ERIM he us ed and he un us ed componen ’s da a eside in
di e en domains and ERIM con ols access o each domain. A new use -mode CPU
ins uc ion (WRPKRU) swi ches access pe missions o domains e icien ly (abou 60
cycles pe swi ch), wi hou ke nel in e en ion. Al hough e icien , his ins uc ions
allows malicious a acke s o escala e hei access pe missions. Hence, by i sel MPK
5

is no su icien o gua an ee secu i y agains malicious o comp omised un us ed
componen s.
ERIM’s con ibu ion is o build secu e memo y isola ion using MPK by (1)
p o iding call ga es o secu ely ans e con ol o he us ed componen a p ede ined
en y poin s wi hou ke nel in e en ion, and (2) use bina y inspec ion o emo e
exploi able bina y code ensu ing ha he swi ch ins uc ion canno be exploi ed.
As a esul , o gain access o sec e da a, an un us ed componen has o in oke
a call ga e ans e ing con ol o he us ed componen . In con as o p io
echniques, ERIM’s memo y isola ion signi ican ly educes he swi ch cos be ween
he us ed and un us ed componen , does no slow down un us ed componen like
language-based echniques, and p o ec s agains malicious a acke s.
We apply ERIM’s design o challenging and p e iously high-o e head use
cases [
74
,
29
,
72
]. Fi s , we isola e equen ly used OpenSSL session keys o a
web se e (nginx) and show scalabili y. Second, we isola e he sa e egion in an
implemen a ion o code-poin e in eg i y (CPI) [
72
]. Thi d, we isola e a managed
un ime (node.js) om an un us ed na i e lib a y (SQLi e). Ou esul s show ha
ERIM p o ides obus memo y isola ion wi h a low o e head o less han 1% o
100,000 swi ches pe second.
O e iew:
In he emainde o his hesis we u he desc ibe he backg ound and
ela ed wo k (Chap e 2), ollowed by de ailed desc ip ion o he design, implemen a-
ion, and e alua ion o Gua da (Chap e 3) and ERIM (Chap e 4). Finally, we
conclude and desc ibe u u e wo k (Chap e 5).
6
CHAPTER 2
Backg ound
In his chap e we p o ide an o e iew o he backg ound wo k on e e ence
moni o s and b ie ly desc ibe exis ing echniques o p o ec con iden iali y and
in eg i y o pe sis en and in-memo y da a. This chap e is only mean o se e
as a backg ound ma e ial o unde s anding he hesis. A de ailed compa ison o
exis ing wo k is p o ided in Sec ions 3.8 and 4.6.
Re e ence moni o ing en o ces secu i y policies a un ime wi hou insis ing ha
he applica ion be bug- ee. Re e ence moni o s in e cep all ele an ope a ions,
e alua e each ope a ion agains he equi ed policy and deny ope a ions when
iola ions a e imminen . We summa ize s a e-o - he-a echniques o e e ence
moni o ing.
Figu e 2.1 depic s possible implemen a ion scena ios o e e ence moni o s.
Re e ence moni o s ha e been implemen ed a di e en abs ac ion laye s wi hin
he so wa e and ha dwa e s ack (see Figu e 2.1a). Each abs ac ion laye gua ds
access o he esou ces p o ided o highe laye s. Re e ence moni o s in highe laye s
(e.g., applica ion, da abase o ile sys em) ely on p o ec ion gua an ees p o ided by
lowe laye s, inc easing he TCB and isk o ci cum en ion o he e e ence moni o .
While moni o ing a an abs ac ion laye , e e ence moni o s can be implemen ed
by isola ing so wa e componen s in us ed execu ion en i onmen s (TEE) [
82
] (see
Figu e 2.1b) o a sepa a e applica ion p ocess [
22
] (see Figu e 2.1c), by sandboxing
7
Ope a ing Sys em
Applica ion
VMM
CPU
Remo e
Hos
Da abase RM
RM
RM
RM
RM
(a) Re e ence moni o a each le el o abs ac ion
CPU
Applica ion
TEE
T us ed
Componen
RM
(b)
Re e ence moni o in us ed execu-
ion en i onmen (TEE)
Ope a ing Sys em
Applica ion RM
(c)
Re e ence moni o in sepa a e appli-
ca ion
Ope a ing Sys em
RM
Applica ion
(d)
Sandboxing applica ion inside a e -
e ence moni o
Ope a ing Sys em
Applica ion
RM
(e) Inlined e e ence moni o
Figu e 2.1: Re e ence moni o implemen a ion scena ios
an applica ion [
143
] (see Figu e 2.1d), o by inlining moni o s in o he applica ion
i sel [1, 72, 29] (see Figu e 2.1e).
En o cemen echniques in non-applica ion laye s e icien ly media e all accesses
o ele an esou ces (e.g., memo y o iles). Usually lowe abs ac ion laye s, such
as he ope a ing sys em (OS) o i ual machine moni o (VMM), in e cep e en s
wi h coa se-g ain in o ma ion om he applica ion. Each laye abs ac s in o ma ion
wi h help om he applica ion. Fo ins ance, implemen ing a pe ile con iden iali y
policy is only possible wi hin he ile sys em laye o abo e. A hese laye s he
accessed ile and i s associa ed policy is s ill a ailable.
Moni o ing a he applica ion laye o e s he mos de ailed in o ma ion abou he
applica ion s a e and execu ion a he cos o a la ge TCB and isk o ci cum en ion.
Inlining he media ion and en o cemen in o he applica ion [
37
,
72
] o e s he abili y
o p o ec he in eg i y o he con ol low o an applica ion a he cos o addi ional
checks o e e y indi ec jump and e u n. En o cing such applica ion le el gua an ees
8
a a lowe laye (e.g., he OS) is in easible, since e e y check would incu high swi ch
cos s be ween he laye and he applica ion.
While nume ous e e ence moni o ing echniques ha e been sugges ed, his
disse a ion ocuses on p o ec ing he con iden iali y and in eg i y o pe sis en and
in-memo y da a. We desc ibe nex he s a e o he a in p o ec ing pe sis en and
in-memo y da a.
2.1 P o ec ing pe sis en da a
In he ollowing we desc ibe echniques o p o ec pe sis en da a om illici elease,
co up ion o dele ion due o bugs, miscon igu a ions, ope a o e o o malicious
a acks. We do no conside ha dwa e ailu es, since eplica ion (such as RAID [
98
])
o da a enc yp ion mi iga e hese h ea s easily.
In gene al, he da a con iden iali y and in eg i y gua an ees in oday’s compu e
sys ems depend on, and a e sp ead ac oss he applica ion, a da abase managemen
sys em, he OS (including he ile sys em) and i ual machine moni o s. Fo example,
each laye en o ces i s own use access con ol p o ec ing agains illici accesses and in
some cases also keeps da a hashes o p o ec he in eg i y. Compa ed o applica ion
laye p o ec ion, lowe laye s p o ide a s onge p o ec ion agains ci cum en ion, bu
ypically do no p o ide a gene ic policy en o cemen and ins ead ocus on speci ic
uses and policies.
Hype iso /OS da a p o ec ion
Nexus [
118
] and TAOS [
139
] a e wo OS-le el
echniques ha en o ce au ho iza ion policies on OS in e aces (e.g., iles, in e -
p ocess communica ion, memo y mappings o p ocess managemen ) p o ec ing da a
con iden iali y. Nexus op ionally main ains a Me kle hash ee o he ile sys em
o p o ide da a in eg i y. In con as o Nexus and TAOS which en o ce policies,
Dune [
19
] and lwC [
74
] a e amewo ks o build a e e ence moni o a he OS
abs ac ion laye media ing he sys em call in e ace and bo h show use cases o
9

CHAPTER 3
Gua da : En o cing da a policies a
he s o age laye
This chap e desc ibes Gua da , a sys em o en o ce con iden iali y and in eg i y
policies on pe sis en da a. B ie ly, he p oblem is ha compu e and s o age sys ems
inc ease in complexi y and so does he isk o da a con iden iali y and in eg i y
om so wa e bugs, secu i y ulne abili ies and human e o . In addi ion, da a
is inc easingly s o ed on hi d-pa y pla o ms, in oducing addi ional isks like
unau ho ized da a use by he hi d pa y. Da a s o ed in hi d-pa y pla o ms ely
on he us and eliabili y o he hi d-pa y p o ide . Today’s sys ems en o ce he
applicable secu i y policy o a ile implici ly in hei code. Fu he mo e, he policy
speci ica ion and en o cemen may sp ead o e di e en subsys ems, inc easing he
isk o ci cum en ion and miscon igu a ion.
Gua da in oduces a e e ence moni o a he s o age laye o ackle hese
challenges. I p o ides a single-poin o policy speci ica ion, con igu a ion and
en o cemen a he s o age laye elying only on i s own policy in e p e e , en o cemen
logic and explici policy dependencies, hus minimizing he TCB and a ack su ace.
The ollowing sec ions desc ibe Gua da ’s design and API, i s decla a i e policy
language, example use cases, an implemen a ion, ela ed wo k and an expe imen al
e alua ion o a p o o ype implemen a ion.
17
3.1 Design
Gua da ’s design was guided by ou p inciples:
1.
Gua da policies a e a ached o iles, sepa a e om code, and speci ied in a
cus om decla a i e policy language. The e o e, he policy o a ile’s da a can
be speci ied concisely in one place and audi ed easily.
2.
Gua da en o ces policies in he s o age laye o minimize he isk o policy
ci cum en ion. Ou implemen a ion o Gua da in a SAN se e , o ins ance,
allows a scalable con igu a ion whe e policies a e en o ced by block se e s
in a machine oom, while clien compu e s and he en e p ise ne wo k a e
un us ed.
3.
Gua da policies s a e me ely wha accesses a e allowed unde which condi ions,
lea ing i o un us ed code how o demons a e compliance wi h a policy. This
sepa a ion keeps he policy language small and policies concise, while shi ing
complexi y o un us ed so wa e and o e head o clien compu e s.
4.
Gua da elies on c yp og aphic ile a es a ions o b idge he seman ic gap
be ween pe - ile policies and block-le el en o cemen . By eques ing an a es a-
ion o a ile’s policy, name and con en hash, an applica ion can e i y ha
Gua da associa es da a and policy co ec ly, independen o he ilesys em o
i s me ada a.
En o cemen a he s o age laye is p e e able, since i minimizes he isk o ci -
cum en ion, and makes i easy o physically p o ec he us ed Gua da componen s
in a machine oom. A design en o cing a a highe laye (e.g., NAS ile se e , VMM
o clien OS laye ) would ex end us o addi ional, and likely mo e dis ibu ed,
componen s. Mo eo e , Gua da is able o b idge he seman ic gap be ween iles and
blocks as wi hou elying on he un us ed ilesys em and i s me ada a.
18
Da a s o ed in Gua da is o ganized in o iles. Fo each policy-p o ec ed ile,
Gua da main ains i s own shadow me ada a, consis ing o an o de ed lis o ex en s,
a unique nume ic iden i ie , a ex ual name s ing ( ypically used o s o e he ile’s
pa hname(s)—mul iple in he case o ha d links), and a e e ence o a policy in
e ec o he ile. The se o nume ic iden i ie s o m a la namespace, while he
se o names ypically encode a con en ional namespace hie a chy main ained by an
un us ed ilesys em. Each ile can ha e i s own policy bu , ypically, a collec ion o
iles sha e he same policy.
The policy o a ile consis s o ou ules, one o each o he pe missions
ead
,
upda e
,
des oy
and
se policy
. Each ule speci ies condi ions on he con ex and
en i onmen unde which he espec i e pe mission holds. Abs ac ly, he
ead
ule
ep esen s he ile’s con iden iali y policy; he
upda e
ule encodes he ile’s in eg i y
policy; he
des oy
ule go e ns when he ile’s iden i ie (name) can be ecycled;
and he
se policy
ule desc ibes when he policy can be changed. S o age commands
ha ead o upda e a ile o i s me ada a check condi ions o he co esponding
policy ules.
Gua da in eg a es wi h ilesys ems. The (un us ed) ilesys em as usual assigns
names and s o age blocks o a ile and ansla es ile eques s in o block eques s
using i s me ada a. Gua da uses i s own shadow me ada a o look up he ile and
policy associa ed wi h a block eques secu ely and e icien ly. Gua da also assigns
i s own unique ile iden i ie s, which can be eused only unde policy con ol.
File a es a ions ie he GDC’s iew o a ile as a sequence o ex en s o an
applica ion’s iew o a named ile, he eby emo ing he need o us he ilesys em
and i s me ada a. By eques ing an a es a ion a e a ile is w i en o ead, an
applica ion can e i y ha i s iew o he ile is iden ical o he GDC’s. Gua da has
suppo o spa se iles. The cu en design assumes ha a block is assigned o a
mos one ile; block sha ing o suppo de-duplica ion, o ins ance, could be added
easily.
19
Gua da ’s p og am logic, called he Gua da con olle o GDC, is in eg a ed
wi h a s o age block de ice and en o ces policies on e e y ead and w i e. The
GDC ex ends he s anda d block-de ice in e ace wi h a ile-le el in e ace, which
allows highe so wa e laye s o (a) c ea e, dele e, ead and upda e se s o ex en s
( iles) using simple ansac ions, (b) associa e policies wi h iles, (c) c yp og aphically
au hen ica e and es ablish secu e sessions, (d) p o ide c eden ials and o he e idence
o policy compliance, and (e) ob ain a es a ions on s o ed iles and hei policies. The
ile-le el in e ace can be used by a Gua da -awa e ilesys em, o by an applica ion
lib a y in combina ion wi h a legacy ilesys em ia IOCTL calls.
3.2 Th ea model
The GDC, me ada a and da a mus be physically p o ec ed om unau ho ized access
and unde ec ed ampe ing. In ou implemen a ion (see Sec ion 3.6.1), da a and
me ada a s o age de ices a e assumed o be physically p o ec ed, e.g., in a machine
oom wi h es ic ed access. Gua da policies a e en o ced, subjec o ex e nal policy
dependencies, ega dless o bugs, miscon igu a ions, o secu i y inciden s ou side he
s o age de ice, including inciden s on any numbe o clien machines.
We make s anda d assump ions abou policies: Co ec policies mus be ins alled
when da a is i s s o ed, and ex e nal dependencies o policies like ime se e s,
clien au hen ica ion keys, and admin au hen ica ion keys mus be us wo hy (in
pa icula , admin au hen ica ion keys can o en be s o ed o line and p o ec ed phys-
ically). Unde hese assump ions, Gua da de ends agains h ea s o con iden iali y
and in eg i y o s o ed da a. In addi ion, Gua da can p o ec he in eg i y and
con iden iali y o iles ans e ed be ween Gua da de ices, and be ween a Gua da
de ice and a clien de ice h ough a secu e channel. This includes h ea s due o
bugs and ulne abili ies in in e media e so wa e laye s including ope a ing sys ems,
ilesys ems, s o age se ices buil on op o Gua da , and ne wo ks, and h ea s due
20
o human negligence and oppo unis ic malice. Gua da is no conce ned wi h da a
a ailabili y. To mask he e ec s o a ha dwa e o media ailu e, loss, o des uc ion
o a Gua da de ice, da a mus be eplica ed on mul iple Gua da de ices wi h
independen ailu e modes.
3.3 In e ace
Gua da ex ends he s anda d block de ice in e ace wi h means o es ablish sessions,
c ea e, upda e and dele e iles, ins all policies, p o ide e idence o policy compliance,
and ob ain a es a ions. In he ollowing, we desc ibe he unc ionali y p o ided by
he in e ace. Table 3.1 shows all Gua da API calls.
3.3.1 Session in e ace
A use applica ion (also called a clien ) in e ac s wi h Gua da in a session. A
secu e, au hen ica ed session mus be used o access iles whose policy equi es clien
au hen ica ion. To access o he iles, no explici session is equi ed. Such use is
concep ually ea ed as pa o a de aul , un us ed session.
A session is es ablished wi h a s anda d handshake p o ocol in which he clien
and Gua da au hen ica e each o he using hei p i a e keys. As pa o he p o ocol,
new, session-speci ic keys a e c ea ed. These keys a e used o enc yp and/o
au hen ica e ( h ough message au hen ica ion codes) all subsequen communica ion
in he session. This p o ec s in- ansi da a and commands om snooping and
modi ica ion in in e media e laye s. Mo eo e , he clien ’s public key (which ac s as
a clien iden i ie ) becomes a ailable du ing e e y policy e alua ion in he session;
hence, Gua da can en o ce policies ha es ic access o a speci ic use . A he
end o he handshake, Gua da e u ns a unique session iden i ie (sId) ha links
la e commands o he session. In he desc ip ion o he emaining in e ace, we omi
21

Session API:
message,sId handshake1(message) Ini ia es he session es ablishmen .
in handshake2(sId,message) Finalizes he session es ablishmen .
in endsession(sId) Te mina es he session sId.
T ansac ion API:
Id openTx(sId,objname) S a s a ansac ion on ile named objname.
in endTx(sId, Id) Commi s a ansac ion.
in
se Policy
(sId, Id,
pId)
Se policy pId o objname.
in
euse
(sId, Id,o ,len,
o ’)
Takes con en o in e al [o ,o +len - 1] and inse s
con en a o ’.
in
esh
(sId, Id,b,len,
bu ,o [, cache lag])
W i e con en o block and add o objname a o se o .
bu
eadTx
(sId, Id,o ,
len [, cache lag])
Reads om objname a o se o .
File/Policy API:
pId c ea ePolicy(sId,policy) S o es policy and e u ns a unique iden i ie pId.
in des oy(sId,objname) Dele es objname’s me ada a and con en .
Con en Hashing API:
hId ini Hash( Id,cu O New)
C ea es hash iden i ie o cu en o new objname.
ce i ica e closeHash(hId)
Compu es hash, c ea es ce i ica e and s o es hash
in cache.
Ce i ica e API:
nonce ge Nonce(sId) Re u ns pseudo- andom nonce alue.
in se Ce i ica e(sId,ce i ica e) P o ide ce i ica e o Gua da .
ce i ica e a es (sId,objname,nonce)
C ea es a ce i ica e a es ing he s a e o obj-
name.
Replica ion/Mig a ion API:
bu pickle(sId,objname, a ge GdKey)
C ea es an enc yp ed bu e bu including
he con en and policy o ile objname which
can only be enc yp ed by a Gua da de ice
wi h a ge GdKey as public key.
in unpickle(sId,bu ,objname)
Dec yp s bu o ex ac con en cand policy
p; c ea es policy pand ile named objname
wi h con en c; associa es he p e iously c e-
a ed policy.
Table 3.1: Gua da In e ace Calls
22
he sId a gumen as i appea s in e e y call. Gua da can wo k wi h any clien -side
in as uc u e o c ea ing, managing and dis ibu ing public keys.
3.3.2 T ansac ion in e ace
Rich policies may equi e mo e han one ead o w i e ope a ion o ansi ion a
ile om one complian s a e o ano he . Fo ins ance, a ile’s in eg i y policy may
equi e ha each upda e inc emen s an embedded e sion coun e . Fo his pu pose,
Gua da suppo s ansac ions consis ing o a sequence o eads and upda es on a
single ile. T ansac ions a e a omic: ei he all he upda es a e pe sis ed o hey a e
all disca ded. Policies may e e o bo h he cu en and new con en o a ile in
a ansac ion, as well as he con en o o he iles. The policy is checked once a
he end o he ansac ion, which commi s i he policy check succeeds, and abo s
o he wise.
We ind his design use ul in encoding policy s a e machines and access-accoun ing
policies, as illus a ed in Sec ion 3.5. Howe e , he design comes wi h a ade-o :
To a oid bu e ing a po en ially unbounded numbe o upda es du ing a ansac ion,
Gua da o bids des uc i e upda es as pa o a ansac ion. Ins ead, new con en
mus be w i en o esh (no cu en ly alloca ed o a policy-p o ec ed ile) ex en s
on disk. This choice mi o s mode n ilesys em designs wi h copy-on-w i e block
alloca ion, e.g., in WAFL, ZFS, and B s [
56
,
125
,
23
]. Ou side a ansac ion,
des uc i e w i es succeed i allowed by he policy.
The ansac ion API adds 5 new commands: openTx, endTx, euse, esh and
eadTx, se Policy. The call
openTx
(sId,objname) s a s a new ansac ion on he ile
named objname. Gene a ing objname is up o he (un us ed) highe laye s, e.g., he
ilesys em. I objname does no exis , a new emp y ile is c ea ed and gi en his name
( his is he only way o c ea e a ile in Gua da ). The call e u ns a ansac ion id
( Id) ha links la e calls o he ansac ion and he session. A ile is upda ed by
23
eusing con en om i s cu en e sion and adding esh con en o c ea e a new
e sion. The call
euse
( Id,o ,len,o ’) akes con en in he logical ange [o ,o +len-1]
om he cu en e sion and inse s i a o se o ’ in he new e sion (inse ion is
pu ely a me ada a ope a ion). The call
esh
( Id,blk,len,bu ,o ) w i es len by es
om bu e bu o he ex en s a ing a by e numbe bon disk and adds he esul ing
ex en o he new e sion a logical o se o . Be o e w i ing he ex en , Gua da
checks ha i is no occupied by any ile (including he ile being modi ied). The
new e sion o he ile may be gi en a new policy wi h he call
se Policy
( Id,pId).
The call bu
eadTx
( Id,o ,len) eads len by es o he ile s a ing a logical o se o
in he ile and e u ns he esul o he bu e bu . The ead ule o he ile’s policy is
e alua ed be o e eading o bu ; i i denies access, he call ails. This en o ces da a
con iden iali y. No e ha we allow by e-le el add essing on iles, so policies can be
e y ine-g ained.
The upda es in a ansac ion a e commi ed wi h he call
endTx
( Id). Gua da
e alua es he upda e ule o he ile’s policy be o e commi ing he new e sion. This
en o ces da a in eg i y. The upda e ule has access o he cu en and new con en o
he ile, as well as ele an me ada a, e.g., he o se s and leng hs o eads and w i es
in he ansac ion. Addi ionally, i he policy has been upda ed, Gua da e alua es
he se policy ule o he ile’s policy; his p o ec s he policy i sel om unau ho ized
changes.
3.3.3 File/Policy in e ace
While ile c ea ions a e implemen ed as ansac ions, ile des uc ion and policy
c ea ion exis as addi ional calls. The
des oy
(objname) call emo es he con en
and me ada a o he ile named objname om Gua da a e success ully e alua ing
he des oy pe mission o he associa ed policy. To educe he equi ed me ada a
space, Gua da allows mul iple iles o be p o ec ed by he same policy. The e o e,
24
he
c ea ePolicy
call e u ns a policy Id (pId) which can be used mul iple imes in
se Policy calls du ing a ansac ion.
3.3.4 Con en cache in e ace
Gua da policies may be con ingen on he cu en con en o one o mo e iles and
he p oposed new con en o he upda ed ile in he con ex o a ansac ion. To
enable he e icien e alua ion o such policies, wo Gua da caches hold ile con en
o use in policy e alua ion. A pe -session cache con ains en ies ha e e o cu en
ile con en s, ei he as a sequence o by es a a gi en ile o se and leng h, o as
he hash o such a sequence. A pe - ansac ion cache con ains he same ypes o
en ies bu e e s o en a i e upda es o a ile. En ies a e added o he cache as a
side-e ec o ead, w i e, esh o eadTx commands wi h app op ia e lags (cache lag).
When a ansac ion commi s, any en ies in he ansac ion cache a e mo ed in o
he session cache, and any exis ing session cache en ies hey supe sede a e e ic ed.
When a ansac ion abo s, he en ies in he ansac ion cache a e disca ded. To
sa is y a policy ha e e s o cu en o pending ile con en , un us ed clien code
is expec ed o ill app op ia e cache en ies by issuing ead/w i e commands be o e
a emp ing a ansac ion commi .
In o de o i e a i ely build con en hashes, Gua da o e s he
ini Hash
call o
s a he hash compu a ion. I he e u ned iden i ie (hId) is speci ied as cache lag
du ing a ead, w i e, esh o eadTx call, hen he espec i e con en is added o
he hash compu a ion. A e a clien inishes he ead/w i e sequence, she closes
he hash ia he
closeHash
call which inalizes he hash compu a ion and s o es
he esul in he espec i e session o ansac ion cache o la e use du ing policy
e alua ion. In addi ion a c yp og aphically signed ce i ica e including he compu ed
hash, ile name and a hash o he associa ed policy is e u ned.
25
We belie e ha policies will be w i en mos ly by p i acy and secu i y expe s.
Fo any applica ion, he e will be a limi ed numbe o basic use ul policies, and
mos sys em adminis a o s, use s o de elope s will me ely selec om a lib a y o
policies, pe haps wi h mino cus omiza ion.
3.5 Policy examples
We illus a e Gua da ’s capabili ies by p esen ing example policies o p o ec exe-
cu ables, log iles and backups. I he
ead
o
upda e
ule o a policy is omi ed,
hen he pe mission is always allowed and i a
se policy
o
des oy
ule is omi ed,
hen ha pe mission is ne e allowed.
3.5.1 P o ec ed execu ables
Fo an execu able ile, i is desi able o p e en acciden al o malicious o e w i ing
o ollback o a p io e sion. A ep esen a i e Gua da policy o accomplish his
is shown below. The policy s a es ha he new con en o he execu able a e any
upda e mus be signed by he so wa e endo (called “Vendo ”) as being e sion 10
o la e . Mo eo e , any policy changes mus be ce i ied wi h he adminis a o ’s
key, kad.
upda e :- ile_name_is(F)∧new_leng h_is(L)∧
(0, L)willHa eHash Nh ∧key_is(K, “Vendo ”)∧
Ksigns ok_hash(F, N, Nh)∧(N≥10)
se policy :- ile_name_is(F)∧
new_pol_hash_is(Nph)∧
kad signs good_policy(F, Nph)
The i s ule allows an upda e o he ile only i he e is a public key
K
belonging
o “Vendo ” (condi ion
key_is
(
K, “Vendo ”
)), which signs ha he ile’s new con en
32

hash,
Nh
, is he
N
h e sion o he execu able (condi ion
Ksigns ok_hash
(
F, N, Nh
))
and
N≥
10. The p edica es
key_is
(
K, “Vendo ”
)and
Ksigns ok_hash
(
F, N,Nh
)a e
e i ied om clien -p o ided ce i ica es signed by a ce i ying au ho i y and he
endo , espec i ely. The second ule allows a change o he execu able’s policy only
i he hash o he new policy, called
Nph
, has been ce i ied by he adminis a o
(condi ion kad signs good_policy(F, Nph)).
P ope ies:
As long as he in eg i y o he endo ’s and admin’s keys is main ained,
iles p o ec ed by he policy canno be o e w i en excep wi h con en signed by he
endo and e sion
≥
10, e en i he en i e sys em is comp omised (w i e in eg i y).
A a ian o his policy can limi con en on he sys em’s boo sec o o endo -signed
boo images, hus p o ec ing he boo sequence om ojans and oo ki s.
3.5.2 Append-only logs
The ollowing policy speci ies an append-only ile ha may be ex ended by anyone
bu modi ied in-place (e.g., o a ed) only by an adminis a o iden i ied by he public
key
kad
. The policy p e en s acciden al o malicious manipula ion o sys em log iles.
upda e :- session_is(kad)∨
(old_leng h_is(Lo)∧new_leng h_is(Ln)∧(Ln ≥Lo)∧
upda ed_loca ions_a e(M)∧disjoin (M, [0, Lo]))
The policy allows an upda e i ei he he session is au hen ica ed by he adminis a o
(condi ion
session_is
(
kad
)) o he ile’s new leng h
Ln
exceeds i s cu en leng h
Lo
and he i s Lo by es o he ile a e no modi ied.
P ope ies:
As long as he in eg i y o he admin’s key is main ained, he policy is
en o ced e en i he sys em is comp omised.
33
3.5.3 P o ec ed backup
Backup iles can be p o ec ed om acciden al o malicious modi ica ion o a ixed
pe iod o ime using he ollowing policy.
upda e :- key_is(K, “TimeSe e ”)∧
Ksigns ime(T)a Ti∧
coun _is(Tj)∧(T+Tj−Ti>endT)
The policy allows modi ica ion o he ile only i he cu en ime exceeds a p e-
de e mined ime
endT
. To en o ce such policies, Gua da elies on signed ce i i-
ca es om ime se e s and a sho - ange in e nal iming coun e . In de ail, he
policy says ha he e should be a key
K
belonging o a ime se e (condi ion
key_is
(
K, “TimeSe e ”
)), which issued a ce i ica e ha he ime was
T
when he
Gua da in e nal coun e had alue
Ti
(condi ion
Ksigns ime
(
T
)
a Ti
), he cu en
in e nal coun e alue is
Tj
(condi ion
coun _is
(
Tj
)) and he cu en ime (calcula ed
as T+Tj−Ti) exceeds he backup end ime endT.
P ope ies:
As long as he in eg i y o he ime se e and i s signing key is
main ained, a ile wi h his policy canno be modi ied be o e he designa ed ime,
e en i he sys em, he admin’s and he ile owne ’s p i a e keys a e comp omised.
3.5.4 Manda o y access logging (MAL)
Legisla ion and o ganiza ional policies o en manda e ha all ead and w i e access
o sensi i e in o ma ion like medical eco ds be logged. Al hough applica ion-le el
solu ions o en o ce such manda o y access logging (MAL) exis , en o cing he policy
in Gua da is desi able because i would inc ease secu i y.
34
Fo his exposi ion, le
P
be he sensi i e ile which mus be p o ec ed by MAL
and le
L
be i s log ile. We assume ha he log ile is append-only, h ough he
policy desc ibed ea lie . The MAL equi emen is h ee- old:
Comple eness
Fo e e y ead on
P
, an en y in
L
should desc ibe who ead and
om whe e in
P
. Fo e e y w i e, a simila en y mus exis in
L
and i mus
addi ionally con ain a hash o he con en w i en.
Causali y
Gi en wo w i e en ies in
L
, he o de in which hey we e applied o
P
should be e iden and, simila ly o a ead and a w i e en y.
P ecision
Call a w i e en y in
L
dangling i i does no co espond o an ac ual
w i e on
P
. Then, ei he dangling en ies should no be allowed in
L
o hey
should be de ec able.
Dangling ead en ies a e usually no a p oblem, because i is in he clien ’s
in e es o es ablish ha i did no ead ce ain da a and, hence, no c ea e dangling
ead en ies. We also desc ibe la e how ead en ies can be made p ecise.
We s a wi h an ob ious s awman policy o
P
, which is comple e, bu does
no p o ide causali y and p ecision. We e ine he design la e . We de ine wo kinds
o en ies o
L
:
may_ ead
(
K, S
), which indica es ha he clien wi h public key
K
has po en ially ead he se
S
o (o ,len) anges om
P
; and
change
(
K, S, H
),
which s a es ha con en wi h hash
H
has been w i en o he anges in
S
. To o ce
logging o eads, we equi e in he
ead
ule o
P
’s policy ha i he ange
R
is ead
by clien
K
, hen an en y
may_ ead
(
K, S
)wi h
R⊆S
exis in
L
. Simila ly, w i e
logging could be o ced h ough P’s upda e ule.
This s awman policy o
P
can be exp essed in he Gua da policy language
because he se
R
o loca ions ead o upda ed is a ailable h ough con ex ual
p edica es in he policy language, he clien
K
is a ailable h ough he p edica e
is_session
(
K
)and
L
’s con en is a ailable h ough he session cache (p edica e
says
).
35
The policy can also be easily sa is ied by he clien : P io o eading o w i ing,
he clien could append an app op ia e en y o
L
and ha e i cached o
P
’s
subsequen policy e alua ion. E en hough his policy sa is ies he MAL equi emen
o comple eness, i does no sa is y causali y and p ecision. No hing in
L
’s policy
p e en s he clien om c ea ing en ies ha a e ne e used and such en ies canno
be dis inguished om o he s ( his iola es p ecision). Mo eo e , no hing in
P
’s
policy p e en s use o L’s en ies ou -o -o de , which iola es causali y.
To ob ain causali y and p ecision, we e ine his s awman design. We embed a
coun e in each en y in
L
and en o ce h ough
L
’s policy ha he coun e inc ease
by 1a each successi e
change
en y and emain he same a each
may_ ead
en y. We
en o ce h ough
P
’s policy ha he alue o he coun e in he las
change
en y ha
has al eady been applied o
P
be w i en a a designa ed locus in
P
. Fu he , he
en y used o jus i y a ead mus ha e a coun e numbe ha ma ches he cu en
coun e in
P
. We desc ibe below how we en o ce hese equi emen s. Assuming ha
hey ha e been en o ced, bo h causali y and p ecision a e sa is ied. Causali y holds
because he policies jus desc ibed o ce ha
change
en ies apply o
P
in inc easing
o de o hei coun e numbe s, and ha a ead co esponding o a
may_ ead
is used
a e all
change
en ies wi h smalle o equal coun e numbe s ha e been applied.
P ecision holds because a
change
en y is dangling i and only i i s coun e numbe
is highe han he coun e in P.
The log’s en ies a e e ised o include coun e numbe s. They ake he o ms
may_ ead
(
N, K, S
)and
change
(
N, K, S, H
), whe e
N
deno es a coun e . We ese e a ixed
locus in
P
o a coun e , called
C
. The log is ini ialized wi h a dummy en y wi h
N
= 0 and
P
is ini ialized wi h
C
= 0. We desc ibe ele an policies o
L
and
P
in
wo ds, omi ing symbolic ep esen a ions o cla i y. We ha e o mally ep esen ed
hese policies in ou p o o ype implemen a ion; expe imen al esul s a e p esen ed in
Sec ion 3.7.5.
36
L’s upda e policy:
Only appends a e allowed and only en ies o he wo designa ed
o ms may be added. I he added en y has he o m
may_ ead
(
N, . . .
), hen
N
mus be copied om he p e ious en y and i he added en y has he o m
change
(
N, . . .
), hen
N
mus be one mo e han he p e ious en y’s coun e .
These equi emen s can be ep esen ed in he Gua da policy language because
he p e ious en y and he new en y a e accessible h ough he session and
ansa ion caches, espec i ely, du ing e alua ion o he upda e ule.
P’s ead policy: L
mus con ain a
may_ ead
en y wi h he same coun e numbe
as
C
and ange se la ge han he ac ual ange ead.
L
’s ele an en y and
C
a e accessible h ough he session cache du ing
P
’s policy e alua ion. In
pa icula ,
C
can be e e enced because Gua da suppo s by e-le el add essing
on iles and he locus o
C
is ixed in ad ance. The clien is esponsible o
speci ying which en y o Lin he session cache sa is ies he policy.
P’s upda e policy: L
mus con ain an en y desc ibing he upda e p ecisely. The
coun e in he en y mus be one mo e han
C
. The upda e mus also inc emen
C
by 1. When e alua ing
P
’s policy,
L
’s ele an en y and he old alue o
C
a e accessible h ough he session cache. The new alue o
C
is accessible
h ough he ansac ion cache.
MAL clien :
The MAL clien mus pe o m some bookkeeping s eps o sa is y he
MAL policy. P io o each access on
P
, app op ia e log en ies mus be c ea ed and
commi ed o Gua da . When c ea ing log en ies, lags mus be se o bu e hem
in he con en cache o use in
P
’s policy e alua ion. A log en y’s cache eco d is
also necessa y o c ea e he nex log en y. Simila ly, when
C
is upda ed, lags mus
be se o cache i o use in u u e policy e alua ions. This app oach ollows om
ou design p inciple o placing he bu den and complexi y o how o sa is y a policy
on he un us ed code.
37

The o e head o c ea ing log en ies o upda es can be educed by commi ing
ansac ions less equen ly (and, hence, equi ing ewe
change
en ies). Simila ly,
he o e head o c ea ing log en ies o eads can be educed by clubbing se e al
an icipa ed eads in o a single
may_ ead
en y. The pe o mance bene i o hese
op imiza ions is subs an ial and we epo on i in Sec ion 3.7.5. Applica ions
ha canno accu a ely es ima e hei ead-se s ahead o ime can simply c ea e
blanke
may_ ead
en ies ha co e he en i e ile and pe iodically commi ead-only
ansac ions accompanied by special log en ies ha speci y p ecisely wha has been
ead in he ansac ion. The p ecise ead se is a ailable o Gua da du ing a commi
ansac ion, so he log en y’s accu acy can be e i ied. This mode o use equi es a
second coun e in log en ies and he sensi i e ile o coun ead-only ansac ions.
3.5.5 O he policy idioms
Many o he common policies can be exp essed in Gua da . Examples include:
(a) Role-based policies whe e access depends on he clien ’s ole in an o ganiza ion
(ce i ica es can ela e clien s o oles), (b) Blacklis (whi elis ) policies whe e access
is denied (allowed) i he clien ’s iden i y exis s in a so ed ile ( he ile’s so edness
can also be en o ced using Gua da policies), and (c) His o y-based policies whe e
access depends on pas e en s ha a e isible o Gua da . The la e can be en o ced
by eco ding e en s in a dedica ed log ile and allowing access o he da a ile only
when he log ile is in ce ain s a es. The MAL policy is a simple his o y-based
policy ha allows access only when he e en o c ea ing an app op ia e log en y
has occu ed.
3.5.6 Exp essi eness
As hese examples demons a e, he Gua da policy language is exp essi e. I
can exp ess con en -based policies like MAL ha p io wo k on decla a i e policy
38
languages canno . Howe e , he language has limi a ions. I disallows ecu si ely-
de ined p edica es and, hence, canno exp ess layou s de ined by i e a ion o ecu sion,
e.g., i canno exp ess ha he con en o a ile be well- o med XML. Such cons ain s
may be checked by a us ed ex e nal e i ie using ce i ica es o communica e
be ween he e i ie and Gua da , o by ex ending he language wi h ecu si e
p edica es.
3.6 Implemen a ion
This sec ion desc ibes he p o o ype implemen a ion o Gua da in a SAN se e
and p esen implemen a ion al e na i es o he Gua da design.
3.6.1 P o o ype
Ou p o o ype is based on he iSCSI En e p ise Ta ge (IET) SAN se e , which
implemen s he se e -side iSCSI p o ocol and p o ides SCSI block s o age access
ia E he ne . IET is in p oduc ion use and a ailable o many Linux dis ibu ions.
Figu e 3.1 depic s he componen le el design. The se e accesses an SSD o he
Gua da me ada a and one o mo e payload disks which a e ei he magne ic- o
lash-based. IET consis s o a ke nel module, which implemen s block accesses, and
a use -le el daemon p ocess, which implemen s iSCSI managemen unc ions. To
implemen Gua da , we ex ended he ke nel module and added a second use -le el
daemon, which implemen s he Gua da in e ace and e alua es policies. The ke nel
module pe o ms upcalls o de e mine i iSCSI block accesses should be allowed. The
se e is con igu ed wi h a small SSD o s o ing Gua da me ada a, as well as one
o mo e magne ic disks o SSDs o he payload da a.
The Gua da daemon main ains wo B- ee index s uc u es on he me ada a
SSD: a block- o- ile index o ind he ile and policy associa ed wi h a gi en block
numbe , and a name- o- ile index o e ie e he ile in o ma ion (se o ex en s,
39
Figu e 3.1: Gua da implemen a ion in a SAN se e
policy, e c.) gi en a ile id. Fo pe o mance, he Gua da daemon main ains a
w i e- h ough DRAM cache o B- ee nodes and policies, backed by he SSD. Upda es
a e pe sis ed on he SSD du ing a ansac ion commi .
When he ke nel module ecei es a block access eques , i passes he access ype
( ead/w i e) and loca ion (disk o se , leng h) o he mul i- h eaded Gua da daemon,
which consul s he block- o- ile index. I he block loca ion is no associa ed wi h
a policy-p o ec ed ile, he access is g an ed. O he wise, he daemon e alua es he
policy and e u ns he esul o he ke nel module. Fo ead eques s, he block ead
is scheduled while checking he pe mission o educe la ency. Du ing a w i e eques ,
he block w i e mus be de e ed un il he Gua da daemon g an s he pe mission.
To educe he numbe o upcalls and policy e alua ions, he ke nel module main-
ains a cache o p e ious policy e alua ion esul s o he o m
hex en , pe missionsi
.
To eed his cache, he Gua da daemon always e u ns he la ges ex en encompass-
ing he p esen ly eques ed block o which he same pe missions hold. The cache is
lushed when a policy changes. This op imiza ion a oids policy e-e alua ion and
sa es he communica ion cos be ween ke nel module and he Gua da daemon in
many cases.
Ou p o o ype’s a ack su ace consis s o he IET managemen in e ace, he
block-de ice in e ace, he Gua da in e ace ex ensions as well as he policy language.
40
Despi e he ela i ely la ge IET codebase, which includes a minimally con igu ed
Linux ke nel, he esul ing a ack su ace is likely o be signi ican ly smalle han
ha o he sys ems and applica ions buil on op o Gua da in mos cases. Ou
Gua da implemen a ion adds less han 20,000 LOC o he exis ing IET codebase,
plus he OpenSSL and glib lib a ies i elies on.
3.6.2 Implemen a ion al e na i es
Gua da can be implemen ed in di e en ways depending on he deploymen and
h ea model. The GDC can be implemen ed using he ollowing mechanisms:
(a)
In a SAN se e o use in a da a cen e , as desc ibed in he p e ious p o o ype
sec ion.
(b)
In eg a ed wi h he mic ocon olle o a hyb id disk o use in an indi idual
machine.
(c)
In a us le wi hin a i ual machine moni o o ope a ing sys em, isola ed
using us ed ha dwa e ea u es like In el SGX [63] o ARM T us Zone [12].
Table 3.3 lis s examples o deploymen scena ios, hei h ea models and us
assump ions. As desc ibed in he h ea model each implemen a ion mus p o ec
he GDC, me ada a and da a om unau ho ized physical access and unde ec ed
ampe ing
Implemen a ion (a) elies on physical p o ec ion, e.g., in a machine oom wi h
access only by us ed employees. A possible deploymen scena io a a Cloud p o ide
p o ec s use da a om bugs and miscon igu a ions in i s in as uc u e and om
oppo unis ic access by employees. The use mus us he Cloud p o ide o p e en
physical access o he SAN se e by all bu us ed employees.
In implemen a ion (b), he GDC is implemen ed as pa o a mic ocon olle
embedded in a hyb id disk. He e, he me ada a and da a a e enc yp ed and au-
41
0.5
1
1.5
2
2.5
3
3.5
4
RR LR SR RW LW SW
Rela i e o e head
Wo kload
iSCSI
Gua da emp y
Gua da ile
Gua da policy
Figu e 3.3: La ency wi h an SSD, ela i e o iSCSI
Figu e 3.3 shows he esul ing a e age access la ency wi h he SSD, ela i e o
he plain iSCSI. E en wi h he as SSD as a block s o e de ice, he Gua da la ency
o e head is gene ally low, bu signi ican o andom w i es (2- old inc ease). The
ac ha ou block s o e SSD pe o ms andom w i es much as e han andom
eads (153
µ
s e sus 233
µ
s), p esumably due o w i e bu e ing in i s in e nal DRAM,
combined wi h he ac ha he policy check canno be o e lapped wi h he access
du ing a w i e, con ibu es o his high ela i e o e head.
No e ha he andom access wo kload is ex eme: The SSD block s o e de ice
is e y as , we a e measu ing he la ency o iny accesses (512 by es) a andom
loca ions o e he en i e disk, and he e a e many iles and policies. Inc easing he
eques size educes he o e head. Fo example, wi h a 4K eques size, he o e heads
dec ease om 29.3% o
RR
and 101.6% o
RW
o 17.7% and 96.1%, espec i ely.
Wi h 128K eques s, he o e heads go u he down o 0.9% and 23.5%, espec i ely.
Mo eo e , as we show nex , e en unde his wo kload he SSD e ains much o i s
la ency ad an age o e he HDD wi h Gua da , and Gua da ’s h oughpu o e head
is e y low on bo h he SSD and he HDD.
Figu es 3.4 and 3.5 compa e he absolu e la encies achie ed on a HDD and SSD
wi h and wi hou Gua da . Despi e Gua da ’s la ge ela i e o e heads o pu ely
andom w i es, he SSD e ains i s owe ing la ency ad an age on such accesses o e
48

0
0.1
0.2
0.3
0.4
0.5
0.6
RR LR SR RW LW SW
Response ime (ms)
Wo kload
iSCSI SSD Gua da policy SSD
Figu e 3.4: Absolu e la ency wi h SSD
0.01
0.1
1
10
RR LR SR RW LW SW
Log. esponse ime (ms)
Wo kload
iSCSI HDD Gua da policy HDD
Figu e 3.5: Absolu e la ency wi h HDD
he HDD (no e ha he y-axis is di e en o SSD and HDD). Wi h he magne ic
HDD, he Gua da la ency o e heads o all con igu a ions a e negligible (below 1%).
Compa ed o a locally a ached SSD, he a e age la ency o a emo ely connec ed
iSCSI SSD inc eases by 0.051 ms, a li le mo e han one ne wo k ound ip (0.047
ms).
3.7.2.2 Read/w i e h oughpu
Nex we examine he ead/w i e h oughpu o he Gua da p o o ype, using he same
con igu a ions as he la ency expe imen . The es clien issues ou 128KB eques s
concu en ly, which is su icien o achie e maximal ead and w i e h oughpu in
49
0
100
200
300
400
500
600
RR LR SR RW LW SW
Th oughpu (MB/s)
Wo kload
iSCSI
Gua da emp y
Gua da ile
Gua da policy
Figu e 3.6: SSD I/O h oughpu
he baseline iSCSI in all cases. Fo each access pa e n in each con igu a ion, we un
he h oughpu es 5 imes; each un issues a o al o 20,000 accesses and s a s a
a andom block wi hin he disk.
Figu e 3.6 shows he absolu e h oughpu wi h he SSD. The esul s shown
a e he a e ages o 5 uns, whe e e o ba s indica e he s anda d de ia ion. The
Gua da o e head is below 2% o all access pa e ns wi h he SSD. Wi h he HDD,
he o e heads a e in he same ange.
The high la ency o e head on andom w i es does no signi ican ly a ec he
h oughpu because policy e alua ion o di e en eques s can be pe o med in
pa allel by he mul i- h eaded Gua da daemon, and o e lapped wi h disk and SSD
accesses o me ada a and blocks.
Mo eo e , compa ed o a locally a ached SSD, he h oughpu o e head is a
mos 3% o all iSCSI and Gua da con igu a ions and wo kloads.
3.7.2.3 I/O pe o mance summa y
While Gua da adds li le la ency o HDD accesses and SSD accesses wi h good
locali y, i has a no iceable la ency o e head on small, pu ely andom w i es o
an SSD. Howe e , his o e head diminishes quickly wi h la ge eques sizes and
50
Policy size Domain size
1 2 4 8 16
12.2 3.4 5.8 10.7 20.4
24.6 10.4 28.9 95.1 345.8
37.0 24.0 121.2 770.5 5,518.1
49.4 50.9 485.3 6,156.4 88,319.3
511.9 104.9 1,951.3 49,234.7 1,411,800.8
Table 3.4:
E alua ion la ency in
µ
s o a ying policy size (numbe o p edica es
and a iables in he policy) and domain size (maximum numbe o cache en ies)
mo e locali y, and can be o e lapped wi h concu en accesses, so ha he SSD’s
h oughpu is no a ec ed.
3.7.2.4 Policy e alua ion o e head
Consis en wi h Da alog, he heo e ical wo s -case e alua ion ime o a policy
ule is in
O
(
m·Dn
), whe e
m
is he size o he ule (numbe o p edica es),
D
is
he size o he domain (bounded by he size o he Gua da cache) and
n
is he
numbe o a iables in he ule. In Table 3.4, we show he measu ed policy e alua ion
ime o syn he ic policies designed o ex ica e wo s -case execu ion om ou policy
in e p e e .
D
a ies along columns o he able and
m
and
n
a y along ows (
m
=
n
in all expe imen s). The esul s ma ch he expec ed complexi y
O
(
m·Dn
). The
able indica es (co ec ly) ha policy e alua ion could be a subs an ial bo leneck o
some policies bu we do no obse e his bo leneck in p ac ice. The a e age policy
e alua ion la ency o he mos complex policy e alua ed, MAL (Sec ion 3.7.5) is only
27.7
µ
s, e en hough he policy has
m
= 4,
n
= 4 and
D
= 40. This is because o a
ca e ul implemen a ion o he policy in e p e e o conside mo e ecen cache en ies
i s . Ou o he
example
policies e alua e e en as e ; he a e age e alua ion ime o
he ime-based policy om he la ency expe imen con igu a ion
Gua da policy
is
only 3.7µs.
51
3.7.2.5 Space equi emen s o me ada a
We quan i y he me ada a s o age equi emen s. Because he me ada a size depends
on he s uc u e o he payload da a, we analyzed he me ada a space equi emen s
o 70,825 ilesys em snapsho s collec ed by Ag awal e al. [
2
]. The snapsho s we e
aken om Windows sys ems wi hin Mic oso co po a ion be ween 2000 and 2004,
and con ain be ween 30k and 90k iles each wi h an a e age ile size be ween 108KB
and 189KB. Fo e alua ion pu poses, we gi e each ile in each snapsho an in eg i y
policy ha disallows modi ica ion p io o a gi en da e. The snapsho s a e mo e
han 10 yea s old a he ime o his w i ing. Because he a e age ile size in
oday’s sys ems has likely inc eased, howe e , ou analysis o Gua da ’s me ada a
equi emen s ela i e o he size o he da a is conse a i e.
The equi ed me ada a can be accommoda ed in a solid s a e memo y o 0.8% o
he da a size o 99.89% o he snapsho s. As a poin o e e ence, e en comme cially
a ailable hyb id disks p o ide a leas 0.8% Flash [
112
] a he ime o his w i ing.
Newe combina ions o Flash/disk de ices achie e much highe Flash o disk capaci y
a ios and his end is p ojec ed o con inue gi en he p ice and space educ ion
a es o lash memo y. Fo example, Apple’s Fusion D i e [
10
] has a a io o 128GB
Flash o a 1TB HDD, which can easily accommoda e all he snapsho s. In all ou
expe imen s, which use o he da a se s, he me ada a i in o only 0.2% o he da a
size.
3.7.2.6 Flash memo y wea
Because Flash memo y can endu e only a limi ed numbe o e ase/p og am cycles,
we mus check ha he SSD used o s o e me ada a will no wea quickly. To be
conse a i e, we assume ha he Flash mus las a leas 10 yea s. The li e ime is
in luenced by he size o he me ada a, he a e o me ada a upda es, and he Flash
capaci y. A smalle capaci y causes he Flash log o w ap a ound as e and leads o
52
0
50
100
150
200
250
300
iozone( /w) bonnie++( /w)
Pe o mance (MB/s)
iSCSI SSD
Gua da policy SSD
iSCSI HDD
Gua da policy HDD
Figu e 3.7: FS benchma ks ead and w i e ( /w) pe o mance
highe u iliza ion, which in u n educes cleaning e iciency and equi es e en mo e
Flash w i es.
Unde he con igu a ion o
Gua da policy
used abo e, we keep ack o how
much wea he Flash expe iences while p esen ed wi h a se ies o me ada a upda es,
i.e., adding and emo ing ex en s o a con en ile picked a andom. En e p ise
en i onmen s ypically deploy single-le el cell (SLC) Flash memo y, which has a
nominal li e ime o 100,000 e ase/p og am cycles. Using only 4GB o such memo y
we can accommoda e up o 19.5M upda es pe day (225 pe second). This is an
ex ao dina ily high upda e a e ha can accommoda e e en he mos w i e-in ensi e
applica ions. Cheape mul iple-le el cell (MLC) and iple-le el cell (TLC) Flash
memo y wi h nominal li e imes o 10,000 and 1,000 e ase/p og am cycles would
suppo up o 1.95M and 195,000 me ada a upda es pe day, espec i ely.
3.7.3 Filesys em benchma ks
Nex , we measu e he pe o mance o he Gua da p o o ype using he s anda d
ilesys em benchma ks
iozone
3.429 and
Bonnie++
1.03. The block s o e was
o ma ed unde ex 4.
iozone
uses ou wo ke h eads o w i e 1GB sequen ially
53

o ou sepa a e iles.
1
La e , each wo ke pe o ms a sequen ial ead o he ile
hey p e iously w o e. Simila ly,
Bonnie++
w i es hen eads 1GB each o 16
iles. Figu e 3.7 shows he pe o mance o he baseline and Gua da unde he
Gua da policy
con igu a ion. The esul s shown a e he a e ages o 5 uns and
e o ba s indica e he s anda d de ia ion. The Gua da o e heads a e below 1.0%
o bo h benchma ks on bo h he HDD and he SSD. No e ha
Bonnie++
uses he
C lib a y unc ions ge c and pu c o pe o m ile eads and w i es, and is he e o e
unable o sa u a e he disks.
Simila o he h oughpu expe imen , he iSCSI SSD esul s a e close o hose
achie ed wi h a locally a ached SSD (a mos 3.5% lowe ).
3.7.4 Use case: Web se e
Nex , we conside he pe o mance o he Gua da p o o ype as pa o a modi ied
Apache Web se e . The se e holds a 220GB s a ic snapsho o English language
Wikipedia a icles om 2008 [
137
] and Wikimedia images om 2005 [
136
], con aining
15 million iles wi h an a e age ile size o 15KB and maximum ile size o
∼
500KB.
The HTTP clien asynch onously eques s HTML pages om he Web se e , using
a wo kload based on he ac ual access coun s o Wikipedia pages du ing one hou on
Ap il 1, 2012 [
138
]. Because ou snapsho is much olde and had ewe a icles a
he ime, we igno e accesses o non-exis ing pages. In o al, abou 350,000 di e en
pages we e accessed in he ace, o which 250,000 a e pa o he 2008 snapsho .
Since we do no ha e access o ime s amps, we dis ibu ed he indi idual accesses
e enly wi hin an hou , and eplayed he i s 100,000 page eques s.
We use he ollowing Gua da policies o p o ec he se e ’s pe sis en s a e:
Con en :
Requi e con en upda es signed by owne s. We andomly assign one o
40,000 owne s o each con en ile.
1We used he command iozone -i 0 -i 1 - 512k -I -c -e -T - 4 -s 1g -F iles
54
200
250
0 10 20 30 40 50 60 70 80 90
Th oughpu (Reques s/s)
Numbe o concu en HTTP eques s
iSCSI
Gua da
Figu e 3.8: Web se e h oughpu
Execu ables/Con ig:
Requi e ha upda es o execu able and con igu a ion iles
be signed by he adminis a o .
Log iles:
The Apache log iles can only be appended, excep wi h an adminis a o
key used o o a e he log.
To sa is y he log ile policy, we added a o al o 51 lines o code o Apache. This
ex a code issues Gua da commands o send con en hashes o Gua da and lush
applica ion and ilesys em caches ( lush & sync) be o e e e y log ile upda e. The
policies p o ec ing he con en , execu ables and con igu a ion iles do no equi e any
modi ica ions o Apache.
Figu e 3.8 shows he a e age h oughpu o h ee uns as a unc ion o he numbe
o concu en HTTP accesses, o plain iSCSI and Gua da (s anda d de ia ion is
below 0.5%). Each un loads 100,000 Wikipedia pages. The h oughpu o e head o
he Gua da con igu a ion o e he unmodi ied iSCSI se e is 1.95% a 60 concu en
eques s, whe e iSCSI eaches i s peak h oughpu , and always wi hin 2.7%. This
esul shows ha he Gua da o e heads mos ly o e lap wi h o he ac i i ies in he
Web se e . The 100,000 page eques s esul in app oxima ely 350,000 Gua da
eads, o an a e age o 3.5 eads pe page. This shows ha a subs an ial numbe
o eads each he Gua da de ice and a e no abso bed by he ilesys em bu e
55
cache. In addi ion, Apache w i es 2.7MB o log eco ds in 170 ansac ions unde he
append-only policy. The e a e no upda es o con en , execu ables and con igu a ion
iles, no log o a ions in he wo kload, bu policies mus s ill be checked du ing each
access.
In e ms o unc ionali y, Gua da p o ec s con en , logs, con igu a ion and
execu able iles om ampe ing by unau ho ized pa ies, which we con i med h ough
aul injec ion expe imen s.
3.7.5 Manda o y access logging
In ou inal expe imen , we pe o m accesses o a ile wi h ou manda o y access
logging (MAL) policy. The policy equi es an app op ia e en y in a sepa a e log
ile o an access o be allowed by Gua da . We use a 64MB p ima y ile wi h o
wi hou he MAL policy in place. The p ima y ile and he log ile eside on di e en
HDDs a ached o he same Gua da IET se e . The e sion coun e embedded in
he p ima y ile is s o ed in Flash memo y no used by Gua da . The clien connec s
o he Gua da de ice and accesses he p ima y ile in h ee di e en con igu a ions.
no log: File accessed wi hou any logging and en o cemen . (ho izon al lines)
log: Accesses logged wi hou policy en o cemen .
Gua da MAL: Accesses logged and policy en o ced by Gua da .
Figu e 3.9 shows he a e age access la ency o 100,000 sequen ial 4KB eads and
w i es o he p ima y ile, a ying he numbe o accesses pe eco ded log en y om
1 o 512. E o ba s indica e he s anda d de ia ion. In he case o a single access
pe log en y, en o cing he MAL policy inc eases he ead/w i e la ency by 11.5%
and 50.6%, espec i ely, o e olun a y logging. The highe cos o logged w i es
compa ed o eads e lec s he need o upda e he e sion numbe . Bo h cos s can
be educed by issuing e sion coun e upda es, log w i es, and p ima y ile accesses
56
0.2
0.4
0.6
0.8
1
1.2
1.4
1 2 4 8 32 128 512
Access la ency (ms)
Accesses pe log en y
Read log
Read Gua da MAL
W i e log
W i e Gua da MAL
ead no log
w i e no log
Figu e 3.9: La ency wi h MAL, olun a y and no logging
in pa allel. Mo eo e , as shown in he igu e, he cos o MAL can be amo ized by
logging se e al accesses in a single log en y, and app oaches he cos o comple ely
unlogged accesses o 512 accesses pe log en y.
3.8 Rela ed wo k
Policy languages based on Da alog.
Many decla a i e policy language a e based
on Da alog and esemble he Gua da policy language in syn ax and seman ics. Some
examples a e Sou ei [
100
], Binde [
33
] and SecPAL [
18
]. Whe eas hese languages
a e gene ic, he Gua da policy language is domain-speci ic and con ains cus om-
designed, s o age- ele an p edica es (Sec ion 3.4). Sou ei, Binde and SecPAL allow
in ensional ( ecu si e, ule-de ined) p edica es, which he Gua da policy language
omi s o keep he implemen a ion simple. These p edica es can be added o Gua da
wi hou any concep ual challenges. DKAL [
52
] ex ends Da alog wi h decla a i e
ules o exchanging au ho iza ion c eden ials in dis ibu ed sys ems. Such ules can
be added o Gua da as well.
TCG s o age wo k g oup speci ica ion.
Al hough de eloped independen ly, he
Gua da a chi ec u e bea s some esemblance o s o age wo k g oup s anda ds o
he us ed compu ing g oup (TCG) [
127
]. Simila o Gua da , he TCG s anda d
57
is easy o deploy and amenable o an e icien implemen a ion, as demons a ed by
ou expe imen al e alua ion.
64

CHAPTER 4
ERIM: Secu e and E icien
In-p ocess Isola ion
The p e ious chap e desc ibed he design, implemen a ion and e alua ion o
Gua da , a s o age laye e e ence moni o en o cing con iden iali y, in eg i y and
accoun ing policies o e pe sis en da a. I en o ces hese policies independen o
highe abs ac ion laye s p o iding a s ong h ea model elying on a small TCB
and a ack su ace.
Howe e , he se o en o ceable policies a e limi ed by he obse able e en s
a he s o age laye . Gua da has no con ol o e da a eleased o an applica ion
wi h su icien access c eden ials. As a esul s an applica ion may leak da a o e he
ne wo k, due o bugs, malicious a acks o miscon igu a ions.
In con as o Gua da , ERIM media es an un us ed applica ion’s execu ion,
in e cep ing ele an applica ion ope a ions like accesses o p i a e da a o ope a ing
sys em se ices. To media e un us ed applica ions, ERIM pa i ions sensi i e da a
and code in o an isola ed and us ed componen , he eby limi ing he e ec s o bugs
and ulne abili ies in he un us ed componen o da a accessible in he un us ed
applica ion only. Fo ins ance, isola ing c yp og aphic keys om he emaining
applica ion can hwa ulne abili ies like he OpenSSL Hea bleed bug [
90
]; isola ing
jump ables can p e en a acks on he in eg i y o an applica ion’s con ol low; and
isola ing a managed language’s un ime can p o ec i s secu i y in a ian s om bugs
and ulne abili ies in co-linked na i e lib a ies.
65
Isola ion o emos equi es memo y isola ion, which p e en s an un us ed com-
ponen om di ec ly accessing he p i a e memo y o o he componen s. B oadly
speaking, memo y isola ion can be en o ced using one o wo app oaches. Fi s ,
we may ins umen he code o un us ed componen s wi h bounds checks p io o
indi ec memo y accesses, ensu ing ha memo y o o he componen s is no accessed
di ec ly, as in SFI [
129
]. Howe e , his app oach imposes o e head on all execu ion o
un us ed componen s due o bounds checks, and i equi es an addi ional echnique
o p e en ci cum en ion o he bounds checks in he ace o con ol- low hijacks [
68
].
The o al o e head is commonly o he o de o ens o pe cen poin s.
The second app oach is o use ha dwa e suppo o memo y isola ion such as
OS o hype iso (ex ended) page ables [
20
,
29
,
74
,
19
]. He e, as access checks in
ha dwa e p e en a componen om accessing he memo y o o he componen s, bu
he e is an o e head on swi ches be ween componen s, since ha dwa e p i ileges mus
be changed, e.g., by swi ching page ables and possibly in alida ing TLB en ies.
Recen wo k on in-p ocess isola ion such as Wedge [
20
], Sh eds [
29
], and ligh -weigh
con ex s (lwCs) [
74
] has educed he cos o ha dwa e-based isola ion somewha .
None heless, swi ching s ill equi es a sys em call and i s cos is signi ican (a 1 us
pe swi ch [
74
] a conse a i e swi ch a e o 100,000 imes a seconds amoun s o 10%
o e head).1
Consequen ly, he e is need o an isola ion echnique ha does no impose
con inuous o e head while a componen execu es and ha also has e y low swi ching
cos on componen ansi ion. ERIM achie es his goal by building on a ecen x86
ISA ex ension called memo y p o ec ion keys o MPKs, also simply called p o ec ion
keys [
64
]. MPKs allow agging each page wi h one o 16 domains, hus pa i ioning
a p ocess’ add ess space in o disjoin domains. A special pe -co e egis e , PKRU,
1
Using x86 memo y segmen a ion ins ead o page ables, as in Na i e Clien [
143
], can educe
he swi ch cos . Howe e , suppo o segmen a ion wi h 64-bi add essing is limi ed and Na i e
Clien has been dep eca ed in a o o he memo y-sa e language WebAssembly [53].
66
de e mines which domains a e accessible. Swi ching pe missions equi es only w i ing
he PKRU egis e wi h a use -mode ins uc ion, which is a ela i ely quick ope a ion
(11–260 cycles on cu en In el CPUs in ou expe imen s).
Howe e , since he PKRU-upda e ins uc ion is use -mode, MPK by i sel
in insu icien o secu i y: Comp omised o malicious componen s can execu e
he ins uc ion o gain unau ho ized access o he memo y o o he componen s.
To p e en his, ERIM addi ionally elies on bina y inspec ion o ensu e ha all
occu ences o his ins uc ion (called WRPKRU) in he bina y a e sa e, i.e., hey
canno be exploi ed o gain unau ho ized access. By design, his p ope y holds e en
i he e is a con ol- low hijack in he un us ed componen . Hence, he e is no need
o complemen ERIM wi h con ol- low in eg i y, which would add o e head.
ERIM dis inguishes i sel om p io wo k on applica ions ha ha e e y high
swi ching a es (~10
5
/s o mo e) and ha addi ionally spend a non i ial amoun o
ime in un us ed componen s. The e a e many such applica ions. We e alua e ou
p o o ype o ERIM on h ee such applica ions. Fi s , in he web se e nginx, we
show ha ERIM can isola e session keys. P o ec ing session keys is a meaning ul
goal, since a acks a ge ed a indi idual use s’ p i acy only need o comp omise
session keys. Second, we show ha ERIM can e icien ly isola e he sa e egion in
code-poin e in eg i y [
72
]. Thi d, we show ha ERIM can be used o isola e a
managed language un ime om possibly buggy na i e lib a ies. In all cases, we
obse e swi ching a es o o de s a leas 10
5
imes/s pe co e. ERIM p o ides s ong
ha dwa e isola ion wi h o e heads less han 1% o e e y 100,000 swi ches/s, which
is conside ably lowe han ha o exis ing echniques.
The ollowing sec ions desc ibe he design, h ee use cases, a p o o ype imple-
men a ion, ela ed wo k and he e alua ion using h ee use cases.
67
4.1 Design
Like p io wo k, ERIM enables a us ed applica ion componen o isola e sensi i e
da a om he es o he un us ed applica ion. Unlike p io wo k, ERIM suppo s
such isola ion wi h low o e head e en a high swi ching a es be ween he un us ed
applica ion and he us ed componen , and wi hou elying on any o he (possibly
expensi e) p o ec ion mechanism, e.g., con ol- low in eg i y. By way o example,
he us ed componen may be a c yp o lib a y ha wan s o isola e c yp og aphic
keys, an inlined e e ence moni o ha wan s o isola e sensi i e me a da a (such as
a ain map o jump ables), o i may be a managed language un ime ha wan s
o isola e om a buggy na i e lib a y. We use he le e
T
o deno e he us ed
componen and U o deno e he emaining un us ed applica ion.
The main p imi i e ERIM p o ides is memo y isola ion—i ese es a egion o
he add ess space accessible exclusi ely om he us ed componen
T
. This ese ed
egion is deno ed
MT
and i can be used by
T
o s o e sensi i e da a. The es o
he add ess space, deno ed
MU
, holds he applica ion’s egula heap and s ack and
is accessible om bo h
U
and
T
. ERIM p e en s
U
om ha ing di ec access o
MT
;
access o
MT
is enabled a omically wi h a con ol ans e o designa ed en y poin s
in
T
, and disabled when
T
e u ns con ol o
U
. Mo e p ecisely, ERIM en o ces he
ollowing in a ian s:
(1) While con ol is in U, access o MT emains disabled.
(2)
Access o
MT
is enabled a omically wi h a con ol ans e o a designa ed en y
poin in T and disabled when T ans e s con ol back o U.
The i s in a ian p o ides isola ion o
MT
om
U
, while he second in a ian
p e en s
U
om con using
T
in o accessing
MT
imp ope ly by jumping in o he
middle o
MT
’s code. Due o he second in a ian , ERIM does no need suppo
om a solu ion o con ol- low in eg i y o secu i y.
68
Con ol ans e s om
U
o
T
and back, wi h he co esponding enabling and
disabling o access o
MT
a e acili a ed by special sequences o ERIM-p o ided code,
dubbed call ga es. Call ga es a e implemen ed in a manne ha p e en s exploi a ion
o hei bina y code o ele a ing p i ileges.
A call ga e enables access o
MT
, execu es a speci ied en y poin o
T
, hen
disables access o
MT
when ans e ing con ol o he us ed componen and
disables access on he way back. A call ga e ans e s con ol only o a designa ed
en y poin in he us ed componen . This en y poin may be a unc ion (i he
us ed componen is a lib a y) o a speci ic sequence o ins uc ions (i he us ed
componen is inlined in o he applica ion).
By design, ERIM imposes negligible o e head on he execu ion o code wi hin
he un us ed applica ion and wi hin he us ed componen , and i s call ga es a e
e y as . Addi ionally, ERIM’s isola ion is s ong—i is de i ed di ec ly om a
ha dwa e secu i y ea u e and i is absolu e, no p obabilis ic (unlike add ess space
layou andomiza ion (ASLR)). Bo h, as swi ching and he s ong isola ion, make
ERIM sui able o p o ec sensi i e da a in high-pe o mance applica ions, e en hose
ha swi ch be ween he applica ion and he lib a y e y equen ly.
4.1.1 Th ea model
ERIM makes no assump ions abou he un us ed componen (
U
) o an applica ion.
U
may beha e a bi a ily and may con ain memo y co up ion and con ol- low
hijack ulne abili ies ha may be exploi ed du ing i s execu ion.
Howe e , ERIM assumes ha he us ed componen
T
’s bina y does no ha e
such ulne abili ies and does no comp omise sensi i e da a by calling back in o
U
while access o
MT
is enabled, h ough in o ma ion leaks, o by mapping execu able
pages wi h unsa e/exploi able occu ences o he WRPKRU ins uc ion.
69

The ha dwa e, he OS ke nel, and a small lib a y added by ERIM o each p ocess
ha uses ERIM a e us ed o be secu e. We also assume ha he ke nel en o ces
s anda d DEP—an execu able page mus no be simul aneously mapped wi h w i e
pe missions. ERIM elies on a lis o legi ima e en y poin s in o
T
p o ided ei he
by he p og amme o he compile , and his lis is assumed o be co ec (see
Sec ion 4.1.5). The OS’s dynamic p og am loade /linke is us ed o in oke ERIM’s
ini ializa ion unc ion be o e any o he code in a new p ocess.
Side-channel and owhamme a acks, and mic oachi ec u al leaks, al hough
impo an , a e beyond he scope o his wo k. Howe e , ERIM is compa ible wi h
exis ing de enses.
4.1.2 In el Memo y P o ec ion Keys (MPK)
To ealize i s goals, ERIM uses he ecen MPK ex ension o he x86 ISA [
64
].
MPK allows associa ing one o 16 p o ec ion keys wi h each memo y page, hus
pa i ioning he add ess space in o up o 16 domains. A pe -co e egis e , called
PKRU, de e mines he cu en access pe missions ( ead, w i e, nei he o bo h) on
each domain o he code unning on ha co e. Access checks agains he PKRU a e
implemen ed in ha dwa e and impose no o e head on p og am execu ion.
Changing access p i ileges equi es w i ing new pe missions o he PKRU egis e
wi h a use -mode ins uc ion, WRPKRU. This ins uc ion is ela i ely as (11–260
cycles on cu en In el CPUs), does no equi e a syscall, changes o page ables, a
TLB lush, o in e -co e synch oniza ion.
Since WRPKRU can be execu ed in use -mode, un us ed code can execu e i
a any poin o ele a e p i ileges and MPK canno p o ide any memo y secu i y
agains un us ed applica ion code by i sel . To ge his p o ec ion, ERIM combines
MPK wi h addi ional bina y inspec ion o ensu e ha any WRPKRU occu ences
70
on execu able pages a e sa e, i.e., hey canno be exploi ed o imp ope ly ele a e
p i ilege.
The mains eam Linux ke nel ully suppo s page- able en ies agged wi h MPK
domains, syscalls o ag he en ies wi h speci ic domains and es o es PKRU egis e s
upon con ex swi ches. Since ha dwa e PKRU checks a e disabled in ke nel mode, he
ke nel has also been modi ied o check PKRU pe missions explici ly be o e accessing
any use space poin e . To elimina e he isk o signal handle s ele a ing p i ileges,
he ke nel upda es he PKRU egis e o i s ini ial se o p i ileges (only ead/w i e
access o domain 0) be o e h owing a signal o he use space.
4.1.3 High-le el o e iew o he design
ERIM can be con igu ed o p o ide ei he comple e isola ion o
MT
om
U
(con-
iden iali y and in eg i y), o only w i e p o ec ion (only in eg i y). Fo simplici y,
we desc ibe he design o comple e isola ion i s . Sec ion 4.1.7 desc ibes how o
con igu e ERIM sligh ly di e en ly o p o ide w i e p o ec ion only.
ERIM’s isola ion mechanism is concep ually simple: I maps
T
’s ese ed memo y,
MT
, and he applica ion’s gene al memo y,
MU
, o wo di e en MPK domains.
I manages MPK pe missions ( he pe -co e PKRU egis e s) o ensu e ha
MU
is
always accessible, while
MT
is ne e accessible when con ol is in
U
. I allows
U
o
secu ely ans e con ol o
T
and back ia call ga es. A call ga e enables access o
MT
using he WRPKRU ins uc ion and immedia ely ans e s con ol o a speci ied
en y poin o
T
, which may be an explici o inlined unc ion. When
T
is done
execu ing, he call ga e disables access o
MT
and e u ns con ol o
U
. This en o ces
ERIM’s wo in a ian s (1) and (2) om Sec ion 4.1. Call ga es ope a e en i ely in
use -mode ( hey don’ use syscalls) and a e desc ibed in Sec ion 4.1.4.
P e en ing WRPKRU exploi a ion
A key di icul y in ERIM’s design is p e-
en ing he un us ed
U
om exploi ing WRPKRU ins uc ions on execu able pages
71
in he add ess space o ele a e p i ileges, e.g. using con ol- low hijack o code-
injec ion a acks. To p e en such exploi s, ERIM elies on bina y inspec ion o
en o ce he in a ian ha only sa e WRPKRU occu ences appea on execu able
pages. A WRPKRU occu ence is sa e i i is immedia ely ollowed by one o he
ollowing:
(A) A p e-designa ed en y poin o T.
(B)
A speci ic sequence o ins uc ions ha checks ha he pe missions se by he
WRPKRU do no include access o
MT
and e mina es he p og am o he wise.
A sa e WRPKRU occu ence canno be exploi ed o execu e un us ed code wi h
access o
MT
. I he occu ence sa is ies (A), hen i does no gi e con ol o
U
a all;
ins ead, i en e s
T
a a designa ed en y poin . I he occu ence sa is ies (B), hen
i would e mina e he p og am immedia ely we e i used by a con ol- low hijack o
enable access o MT.
ERIM’s call ga es use only sa e WRPKRU occu ences and, he e o e, pass
ou bina y inspec ion. Ou modi ied ke nel inspec s any page p io o mapping
i in execu able mode, en o cing he in a ian ha all occu ences o WRPKRU
on execu able pages a e sa e. Sec ion 4.1.5 p o ides de ails o his ke nel bina y
inspec ion mechanism.
C ea ing sa e bina ies
An impo an ques ion is how o cons uc bina ies ha
do no ha e unsa e WRPKRUs. On x86, an inad e en o unin ended execu able
WRPKRU may a ise spanning he by es o wo adjacen ins uc ions o as a subse-
quence in a longe ins uc ion. To elimina e inad e en WRPKRUs, we de elop a
bina y ew i ing mechanism ha ew i es any sequence o ins uc ions con aining an
inad e en WRPKRU o a unc ionally equi alen sequence wi hou any WRPKRUs.
Simila ly, he mechanism also al e s delibe a e uses o WRPKRU which olun a ily
swi ch domains by inse ing p i ilege checks. The mechanism can be deployed as
72
1xo ecx , ecx
2xo edx , edx
3mo PKRU_ALLOW_TRUSTED, eax
4WRPKRU // cop ies eax o PKRU
6// Execu e us ed componen ’ s code
8xo ecx , ecx
9xo edx , edx
10mo PKRU_DISALLOW_TRUSTED, eax
11WRPKRU // cop ies eax o PKRU
12cmp PKRU_DISALLOW_TRUSTED, eax
13j e con inue
14s y s c a l l exi // e mina e p og am
15con inue :
16// co n ol e u ns o he un us ed a pplic a io n he e
Lis ing 4.1:
Call ga e implemen a ion in assembly. The code o he us ed
componen ’s en y poin may be inlined by he compile on line 6, o he e may be
an explici di ec call o i .
a compile pass, in eg a ed wi h ou bina y inspec ion, o by s a ically ew i ing
bina ies p io o hei use as explained in Sec ion 4.2
4.1.4 Call ga es
A call ga e ans e s con ol om
U
o
T
, enabling access o
MT
, hen uns code
om a designa ed en y poin o
T
, and la e e u ns con ol o
U
a e disabling
access o
MT
. This equi es wo WRPKRUs. The p ima y challenge in designing
he call ga e is ensu ing ha bo h hese WRPKRUs a e sa e in he sense explained
in Sec ion 4.1.3.
Lis ing 4.1 shows he assembly code o a call ga e. WRPKRU expec s he new
PKRU alue in he
eax
egis e and equi es ecx and edx o be 0. The call ga e
wo ks as ollows. Fi s , i se s PKRU o enable access o
MT
(lines 1–4). The mac o
PKRU_ALLOW_TRUSTED is a PKRU se ing ha allows access o
MT
. Nex ,
he call ga e passes con ol o he designa ed en y poin o
T
(line 6). The en y
poin ’s code may be in oked ei he by a di ec call, o i may be inlined he e.
73
he p esen alue o he PKRU is no PKRU_ALLOW_TRUSTED, indica ing ha
he syscall does no o igina e om
T
. To gain access o es ic ed esou ces,
U
has
o in oke T, which can ac as a e e ence moni o .
4.2 Rew i ing inad e en WRPKRUs
Fo secu i y, ou bina y inspec ion (see Sec ion 4.1.5) equi es bina ies o ha e only
sa e WRPKRU occu ences. WRPKRUs emi ed pu pose ully by a compile can
be made sa e by changing he compile sligh ly o inse he check on lines 12–15
o Figu e 4.1 a e e e y po en ially unsa e WRPKRU. Inad e en WRPKRUs—
hose ha occu unin en ionally as pa s o longe x86 ins uc ions o spanning wo
consecu i e x86 ins uc ions—a e mo e in e es ing. In his Sec ion, we desc ibe
a ew i e s a egy o elimina e such WRPKRUs. The s a egy is comple e: Any
sequence o x86 ins uc ions con aining an inad e en WRPKRU can be ew i en
o a unc ionally equi alen sequence wi hou any WRPKRUs.
4.2.1 Rew i e s a egy
WRPKRU is a 3 by e ins uc ion, 0x0F01EF. WRPKRU sequences ha span wo
o mo e ins uc ions can be “b oken” by inse ing a 1 by e nop like 0x90 be ween
any wo consecu i e ins uc ions. 0x90 does no coincide wi h any indi idual by e
o WRPKRU (0x0F, 0x01 and 0xEF), so his inse ion canno gene a e a new
WRPKRU.
A WRPKRU sequence ha lies en i ely wi hin a longe ins uc ion can be
elimina ed by inding an equi alen sequence o ins uc ions. Doing so sys ema ically
equi es unde s anding x86 ins uc ion coding. An x86 ins uc ion consis s o :
(i) An opcode ield possibly wi h p e ix.
80

(ii)
A MOD R/M ield ha de e mines he add essing mode and includes he code
o a egis e ope and.
(iii) An op ional SIB ield ha speci ies egis e s o indi ec memo y add essing.
(i )
Op ional displacemen and/o immedia e ields which speci y cons an o se s
o memo y ope a ions and o he cons an ope ands.
Ou s a egy o ew i ing an ins uc ion con aining WRPKRU as a subsequence
depends on he ields wi h which he WRPKRU subsequence o e laps. Table 4.1
summa izes ou s a egy. I he WRPKRU sequence lies en i ely in he opcode ield,
hen he ins uc ion is WRPKRU. As explained ea lie , his case is handled by
adding a check (B) a e he ins uc ion o make i sa e.
I he sequence o e laps wi h he MOD R/M ield, we change he egis e code in
he MOD R/M ield, which elimina es he WRPKRU sequence. This change equi es
a ee egis e . I one exis s, we use i , else we ew i e o push an exis ing egis e o
he s ack, use i in he ins uc ion, and pop i back. (Lines 2 and 3 in Table 4.1.)
I he sequence o e laps wi h he displacemen o he immedia e ield, we change
he mode o he ins uc ion o use a egis e ins ead o a cons an . The cons an
is compu ed in he egis e be o e he ins uc ion (lines 4 and 6). I a ee egis e
is una ailable, we push and pop one. Two ins uc ion-speci ic op imiza ions a e
possible. I he ins uc ion is jump-like, hen he jump a ge can be eloca ed in he
bina y; his changes he displacemen in he ins uc ion, elimina ing he need o a
ee egis e (line 5). I he ins uc ion is an associa i e ope a ion such as addi ion,
hen he ope a ion can be pe o med in wo inc emen s wi hou an ex a egis e
(line 7).
We ne e ew i e he SIB ield. This does no a ec he comple eness o ou
echnique since any WRPKRU mus o e lap wi h a leas one non-SIB ield ( he SIB
ield is 1 by e long while WRPKRU is 3 by es long).
81
O e lap wi h Cases Rew i e s a egy ID Example
Opcode Opcode = WRPKRU Inse p i ilege check a e WRPKRU 1
Mod R/M Mod R/M = 0x0F
Change o unused egis e + mo e com-
mand
2
add ecx, [ebx + 0x01EF0000]
→
mo eax, ebx; add ecx, [eax +
0x01EF0000];
Push/Pop used egis e + mo e com-
mand
3
add ecx, [ebx + 0x01EF0000]
→
push eax; mo eax, ebx; add ecx,
[eax + 0x01EF0000]; pop eax;
Displacemen Full/Pa ial sequence Change mode o use egis e 4
add eax, 0x0F01EF00
→
(push ebx;)
mo ebx, 0x0F010000; add ebx,
0x0000EA00; add eax, ebx; (pop
ebx;)
Jump-like ins uc ion
Mo e code segmen o al e cons an used
in add ess
5
call [ ip + 0x e 010 ]
→
call [ ip +
0x e 0100]
Immedia e Full/Pa ial sequence Change mode o use egis e 6
add eax, 0x0F01EF
→
(push ebx;)
mo ebx, 0x0F01EE00; add ebx,
0x00000100; add eax, ebx; (pop ebx;)
Associa i e opcode
Apply ins uc ion wice wi h di e en im-
media es o ge equi alen e ec
7
add ebx, 0x0F01EF00
→
add ebx,
0x0E01EF00; add ebx, 0x01000000
Table 4.1: Rew i e s a egy o in a-ins uc ion occu ences o WRPKRU
82
4.2.2 Implemen ing he ew i ing
Fo bina ies ha can be ( e)compiled om sou ce, ew i ing can be added o he
codegen phase o he compile , which con e s he in e media e ep esen a ion (IR)
o machine ins uc ions. Whene e codegen ou pu s an inad e en WRPKRU, he
su ounding ins uc ions in he IR can be eplaced wi h equi alen WRPKRU- ee
ins uc ions as desc ibed abo e, and codegen can be un again on he upda ed IR.
Fo bina ies ha canno be ecompiled, he ew i e s a egy can be in eg a ed
wi h ou bina y inspec ion handle (Sec ion 4.1.5). I he handle disco e s an unsa e
WRPKRU on an execu able page du ing i s scan, i can o e w i e he page wi h
1-by e ap ins uc ions, make i execu able, and s o e he o iginal page in ese e
wi hou enabling i o execu ion. Subsequen ly, i he e is a jump in o he execu able
page, a ap occu s and he ap handle disco e s an en y poin in o he page. I can
hen disassemble he ese ed page om ha en y poin on, ew i ing any disco e ed
WRPKRU occu ences, and copy he WRPKRU- ee ins uc ion sequences back o
he execu able page. To p e en o he h eads om execu ing pa ially o e w i en
ins uc ion sequences, we ac ually ew i e a esh copy o he execu able page wi h
he WRPKRU- ee sequences, and hen swap his ew i en copy o he execu able
page. This echnique is anspa en o he applica ion, has an o e head p opo ional
o he numbe o en y poin s in o o ending pages (we disassemble om e e y en y
poin only once) and main ains he in a ian ha only sa e WRPKRU sequences a e
execu able.
In con as o ew i ing a un ime, a bina y can be s a ically ew i en o emo e
all inad e en WRPKRUs. Compa ed o a compile o un ime app oach, s a ic
bina y ew i ing does no ely on sou ce code a ailabili y and does no imposes
addi ional un ime o e head. I s d awback is he dependence on a s a ic ew i e ool
which can success ully ew i e a bina y. In o de o success ully ew i e a bina y,
83
ools like Dynins [
34
] equi e a ull disassembly o he bina y. Recen ly Bauman e
al. [16] ha e p oposed a s a ic ew i e echnique emo ing his dependency.
Ou s a ic ew i e app oach, simila o he bina y inspec ion, pe o ms a simple
linea scan o he bina y o ind all hose inad e en occu ences o he 3-by e
WRPKRU sequence in execu able sec ions. Nex , using any bina y ew i ing ool, e.g.,
Dynins [
34
], we disassemble he bina y o he ex en possible, and ew i e ins uc ions
o elimina e hese inad e en occu ences. We use he p e iously desc ibed ew i ing
s a egy (see Sec ion 4.2.1 o able 4.1). Occu ences o WRPKRU in pa s ha we
canno disassemble a e handled by he bina y inspec ion and ew i ing a un ime as
desc ibed in he p e ious Sec ion.
We e alua e he e ec i eness o s a ically ew i ing bina ies in Sec ion 4.5.1.4.
4.3 Use Cases
ERIM di e s om p io wo k by p o iding e icien isola ion in applica ions whe e
swi ches be ween us ed and un us ed componen s a e e y equen , o he o de
o 10
5
o 10
6
imes a second. We desc ibe h ee such use-cases he e, and show in
Sec ion 4.5 ha ERIM’s o e head is low on all o hem.
4.3.1 Isola ing c yp og aphic keys in web se e s
Isola ing long- e m SSL keys o p o ec om web se e ulne abili ies such as he
Hea bleed bug [
90
] is well-s udied [
74
,
75
]. Howe e , long- e m keys a e accessed
ela i ely in equen ly (only a ew imes pe use session). Session keys ha a e
accessed a mo e equen ly (up o 10
6
imes a second pe co e in a high h oughpu
web se e like nginx) ha e no been isola ed so a . Isola ing sessions keys is also
ele an as hese keys p o ec he con iden iali y o indi idual use s. No exis ing
echnique can isola e session keys wi hou signi ican o e head.
84
Taking ERIM’s e icien isola ion in o accoun , an ERIM-p o ec ed componen
can isola e he c yp og aphic keys and c yp og aphic me hods. This esul s in a small
TCB and a ack su ace. OpenSSL does no implemen isola ion wi hin he lib a y,
hence we pa i ioned OpenSSL’s low-le el c yp o lib a y (libc yp o) o isola e he
session keys and basic c yp o ou ines, which un as
T
, om he es o he web se e ,
which uns as
U
. The ou e laye o OpenSSL p o ides he high-le el SSL/TLS
in e ace, whe eas he inne , isola ed laye secu ely s o es he c yp og aphic keys
and pe o ms c yp og aphic ope a ions. When using his ERIM-p o ec ed OpenSSL
wi hin a se e applica ion, a new SSL/TLS session c ea es a session key wi hin he
T
. Messages o his session can only be en-/dec yp ed wi hin he
T
. This e icien ly
p o ec s he c yp og aphic keys o se e applica ions om memo y ulne abili ies.
4.3.2 CPI/CPS
Code-poin e in eg i y (CPI) [
72
] is a compile ans o m ha p e en s con ol- low
hijacks by isola ing sensi i e objec s—code poin e s and objec s ha can lead o
code poin e s—in a sa e egion ha canno be w i en wi hou bounds checks. CPS
is a ligh e , less-secu e a ian o CPI ha isola es only code poin e s. Swi ching
a es o he sa e egion can be e y high in CPI, o he o de o 10
6
swi ches pe
second on s anda d benchma ks. A key ques ion in CPI/CPS is how o isola e he
sa e egion. The o iginal pape uses ASLR on x86-64 o i s e alua ion. ASLR
has almos no un ime o e head, bu i is now known o be ine ec i e o da a
isola ion [113, 60, 39, 49, 94].
We show ha ERIM can p o ide s ong isola ion o he sa e egion a low cos .
To do his, we o e ide he CPI/CPS-enabled compile ’s in insic unc ion o w i ing
he sensi i e egion o use a call ga e a ound an inlined sequence o
T
code ha
pe o ms a bounds check be o e he w i e. (MemSen y [
68
] also p oposes he use
85

o MPKs o isola ing he sa e egion, bu does no ac ually build o e alua e his
use-case.)
4.3.3 Na i e lib a ies in managed un imes
Applica ions unning on managed un imes such as a Ja a o Ja aSc ip VM o en
ely on hi d-pa y na i e code lib a ies. A ele an secu i y goal is o isola e he
managed un ime om bugs and ulne abili ies in he na i e lib a ies. ERIM can
be used o his pu pose by mapping he managed un ime o
T
and he na i e
lib a y(ies) o
U
. We es his by isola ing a na i e SQLi e plugin om Node.js.
SQLi e and Node.js a e, espec i ely, a s a e-o - he-a C da abase lib a y and a
s a e-o - he-a managed un ime o Ja aSc ip [121, 91].
4.4 Implemen a ion
We ha e implemen ed a p o o ype o ERIM on Linux. The p o o ype includes a 77
line Linux Secu i y Module (LSM) ha in e cep s all mmap and mp o ec calls o
p e en
U
om mapping pages in execu able mode, and p e en s
U
om o e iding
he bina y inspec ion handle . We also added 26 LoC in ke nel hooks needed o
his module. Ou implemen a ion also includes he ERIM un ime lib a y, which
p o ides a memo y alloca o o e
MT
, call ga es, he ERIM ini ializa ion code, and
bina y inspec ion. These comp ise 569 LoC.
Sepa a ely, we ha e implemen ed he ew i ing logic o elimina e inad e en
WRPKRU occu ences (abou 2250 LoC). While we ha e no ye in eg a ed he
logic in o ei he a compile o ou inspec ion handle , we ha e in eg a ed i in o a
s andalone bina y ew i ing ool ha uses Dynins [
34
] o disassemble bina ies. The
bina ies used in ou e alua ion do no ha e any unsa e WRPKRU occu ences and
do no load any lib a ies a un ime.
86
Call ype Cos (cycles)
Inlined call (no swi ch) 5
Di ec call (no swi ch) 8
Indi ec call (no swi ch) 19
Inlined call + swi ch 60
Di ec call + swi ch 69
Indi ec call + swi ch 99
ge pid sys em call 152
lwC swi ch [74] (Skylake CPU) 6050
Table 4.2: Cycle coun s o basic call and e u n
4.5 E alua ion
We e alua e ERIM on mic obenchma ks and on he h ee applica ions men ioned
in Sec ion 4.3. We pe o m ou expe imen s on Dell Powe Edge R640 machines
wi h 16-co e MPK-enabled In el Xeon Gold 6142 2.6GHz CPUs (wi h Tu bo Boos
and SpeedS ep disabled), 384GB memo y, 10Gbps E he ne links, unning Debian
8. Fo he CPI expe imen , we use he Le ee p o o ype 0.2 a ailable om
h p:
//dslab.ep l.ch/p oj/cpi/
and Clang 3.3.1 including i s CPI compile pass,
un ime lib a y ex ensions and link- ime op imiza ion. Fo he nginx expe imen , we
use nginx 1.12.1 and OpenSSL 1.1.1 and he ECDHE-RSA-AES128-GCM-SHA256
ciphe . Fo he managed language un ime expe imen , we use Node.js 9.11.1 and
SQLi e 3.22.0. Fo a compa ison base line we use SQLi e compiled o WebAssembly
ia emsc ip en 1.37.37’s WebAssembly backend [36].
4.5.1 Mic obenchma ks
4.5.1.1 Swi ch cos
We pe o med a mic obenchma k o measu e he o e head o in oking a unc ion
wi h and wi hou a swi ch o a us ed componen . The unc ion adds a cons an o
an in ege a gumen and e u ns he esul . Table 4.2 shows he cos o in oking
87
he unc ion, in cycles, as an inlined unc ion (I), as a di ec ly called unc ion (DC),
and as a unc ion called ia a unc ion poin e (FP). Fo e e ence, he able also
includes he cos o a simple syscall (ge pid) and he cos o a swi ch on lwCs, a
ecen in-p ocess isola ion mechanism based on s anda d page able p o ec ions [
74
].
In ou mic obenchma k, calls wi h an ERIM swi ch a e be ween 55 and 80 cycles
mo e expensi e han hei no-swi ch coun e pa s. The mos expensi e indi ec call
cos s less han he simples sys em call (ge pid). ERIM swi ches a e up o 100x
as e han lwC swi ches.
Because he CPU mus no eo de loads and s o es wi h espec o a WRPKRU
ins uc ion, he o e head o an ERIM swi ch depends on he CPU pipeline s a e
a he ime o he WRPKRUs in he swi ch. In expe imen s desc ibed la e in his
Sec ion, we obse ed a e age o e heads anging om 11 o 260 cycles pe swi ch. A
a clock a e o 2.6GHz, his co esponds o o e heads be ween 0.04% and 1.0% o
100,000 swi ches pe second, which is signi ican ly lowe han he o e head o any
bounds-check, ke nel- o hype iso -based isola ion.
4.5.1.2 Emula ing MPK’s swi ch cos
Following we desc ibe how o emula e he WRPKRU ins uc ion. This enables
us o compa e agains echniques who’s en i onmen does no suppo MPK. The
WRPKRU ins uc ion mo es he alue o he eax egis e o he PKRU egis e .
Howe e , since he ins uc ion impac s he alidi y o subsequen loads/s o es, he
ins uc ion canno be e-o de ed ela i e o su ounding load/s o e ins uc ions in
he execu ion pipeline. We emula e he cos o WRPKRU using a sequence o
xo ins uc ions ha ha e no ne unc ional e ec (excep consuming CPU cycles),
ollowed by RDTSCP, which causes a pipeline s all and p e en s ins uc ion e-
o de ing. The emula ion code is shown in Lis ing 4.2.
88
o ( i = 0; i < 5; i++) {
xo eax , ecx
xo ecx , eax
xo eax , ecx
}
d scp
Lis ing 4.2: WRPKRU emula ion using RDTSCP and Xo Swi ch
Benchma k Swi ches/sec CPI O e head (%)
ERIM EMUL
403.gcc 13,454,647 22.3 22.68
445.gobmk 1,055,994 1.77 1.76
447.dealII 1,270,582 0.56 0.17
450.soplex 408,192 0.6 2.56
464.h264 e 1,684,572 1.22 0.86
471.omne pp 36,578,718 144.02 142.26
482.sphinx 1,148,883 0.84 0.65
483.xalancbmk 21,448,977 52.22 51.74
Table 4.3:
Domain swi ch a es o selec ed SPEC CPU benchma ks and o e heads
o ERIM-CPI and EMUL-CPI, ela i e o s anda d CPI.
Valida ion
To alida e ha ou emula ion es ima es o e heads close o hose o he
ac ual WRPKRU ins uc ion, we e- un he CPI/CPS benchma ks o Sec ion 4.5.2
wi h WRPKRU emula ion in place o he ac ual WRPKRU ins uc ion. Figu e 4.1
ep oduces ERIM’s ela i e o e heads on a ious benchma ks om Figu e 4.2 bu
addi ionally lis s he ela i e o e heads using he WRPKRU emula ion (lines EMUL-
CPI and EMUL-CPS). Table 4.3 lis s he p ecise o e heads o CPI on benchma ks
ha ha e high swi ching a es. As can be seen, he o e heads o he emula ion a e
e y close o ac ual ERIM’s o e heads on all benchma ks.
No e om Table 4.3 ha ou emula ion is no pe ec , bu qui e close o he
ac ual in e ms o o e head. Emula ing he pe o mance o WRPKRU pe ec ly is
di icul since emula ion canno exac ly ep oduce he e ec s o WRPKRU on he
execu ion pipeline. (WRPKRU mus p e en he eo de ing o loads and s o es wi h
espec o i sel .) Depending on he speci ic benchma k, ou emula ion sligh ly o e -
89
Benchma k Swi ches/sec ERIM-CPI o e head
ela i e o o ig. CPI in %
403.gcc 16,454,595 22.30%
445.gobmk 1,074,716 1.77%
447.dealII 1,277,645 0.56%
450.soplex 410,649 0.60%
464.h264 e 1,705,131 1.22%
471.omne pp 89,260,024 144.02%
482.sphinx3 1,158,495 0.84%
483.xalancbmk 32,650,497 52.22%
Table 4.5:
Domain swi ch a es o selec ed SPEC CPU benchma ks and o e heads
o ERIM-CPI wi hou bina y inspec ion, ela i e o he o iginal CPI wi h ASLR.
Table 4.5 also shows he o e head o ERIM-CPI excluding bina y inspec ion,
ela i e o he o iginal CPI o e ASLR (no ela i e o an unp o ec ed baseline
as in Figu e 4.2). This ela i e o e head is exac ly he cos o ERIM’s swi ching.
Depending on he benchma k, i a ies om 0.03% o 0.16% o 100,000 swi ches
pe second o , equi alen ly, 7.8 o 41.6 cycles pe swi ch. These esul s indica e ha
ERIM can suppo inlined e e ence moni o s wi h swi ching a es o up o 10
6
imes
a second wi h low o e head. Beyond his a e, he o e head becomes no iceable.
4.5.2.2 CPS
The esul s o CPS a e simila o hose o CPI, bu he o e heads a e gene ally
lowe . Rela i e o anilla SPEC wi h no p o ec ion, he geome ic means o he
o e heads o he o iginal CPS and ERIM-CPS ac oss all benchma ks a e 1.1% and
2.4%, espec i ely. ERIM-CPS o e head ela i e o he o iginal CPS is wi hin 2.5%
on all benchma ks, excep excep pe lbench, omne pp and xalancbmk, whe e i
anges up o 17.9%.
4.5.3 P o ec ing session keys in nginx
Nex , we use ERIM o isola e SSL session keys in a high pe o mance web se e ,
nginx. We modi ied OpenSSL’s libc yp o o isola e he keys and he unc ions o
96

File
size
(KB)
Th oughpu Swi ches/s CPU
load
na i e
(%)
Na i e
( e-
q/s)
ERIM
el.
(%)
0
95,761
95.83 1,342,605 100.0
1
87,022
95.18 1,220,266 100.0
2
82,137
95.44 1,151,877 100.0
4
76,562
95.25 1,073,843 100.0
8
67,855
95.98 974,780 100.0
16
45,483
97.10 820,534 100.0
32
32,381
97.31 779,141 100.0
64
17,827
100.00 679,371 96.7
128 8,937 99.99 556,152 86.4
Table 4.6:
Nginx h oughpu wi h a single wo ke . The s anda d de ia ion is below
1.1% in all cases.
AES key alloca ion and enc yp ion/dec yp ion in o ERIM’s
T
and use ERIM call
ga es o in oke hese unc ions.
Ou goal is o measu e ERIM’s o e head on he peak h oughpu o nginx. To
s a , we con igu e nginx o un a single wo ke pinned o a CPU co e, and connec
o i emo ely om 4 concu en ApacheBench (
ab
) [
8
] ins ances o e HTTPS wi h
keep-ali e. Each ins ance simula es 75 concu en clien s. The clien s all eques
he same ile, whose size we a y om 0 o 128KB ac oss expe imen s. Figu e 4.3b
shows he h oughpu o ERIM-p o ec ed nginx ela i e o ou baseline (na i e
nginx wi hou any p o ec ion) o di e en eques sizes, measu ed a e an ini ial
wa m-up pe iod. Figu e 4.3a shows he absolu e h oughpu s in eques s/s in he
same expe imen . All numbe s a e a e ages o 10 uns.
ERIM-p o ec ed nginx p o ides a h oughpu wi hin 95.18% o he unp o ec ed
se e o all eques sizes. To explain he o e head u he , we lis he numbe o
ERIM swi ches pe second in he nginx wo ke and he wo ke ’s CPU u iliza ion
in Table 4.6 o eques sizes up o 128KB. The o e head shows a gene al end up
o eques s o size 32 KB: The wo ke ’s co e emains sa u a ed bu as he eques
size inc eases, he numbe o ERIM swi ches pe second dec ease, and so does
97
0
20000
40000
60000
80000
100000
0kb
1kb
2kb
4kb
8kb
16kb
32kb
64kb
128kb
Reques s/s
File size
Na i e
ERIM
(a) A e age numbe o eques s pe second o na i e and ERIM.
0
0.2
0.4
0.6
0.8
1
0kb
1kb
2kb
4kb
8kb
16kb
32kb
64kb
128kb
No malized Th oughpu
File size
Na i e ERIM
(b) No malized h oughpu o na i e (no p o ec ion).
Figu e 4.3:
Nginx h oughpu wi h one wo ke , wi h and wi hou ERIM p o ec ion,
wi h a ying eques sizes. S anda d de ia ions we e all below 1.1%.
98
ERIM’s ela i e o e head. The obse a ions a e consis en wi h an o e head o abou
0.31%–0.44% o 100,000 swi ches pe second. Fo eques sizes o 64KB and highe ,
he 10Gbps ne wo k ca d sa u a es and he wo ke does no u ilize i s CPU co e
comple ely in he baseline. The ee CPU cycles abso b ERIM’s CPU o e head, so
ERIM’s h oughpu ma ches ha o he baseline.
No e ha his is an ex eme es case o a web se e . He e, he web se e does
almos no hing and se es he same cached ile epea edly. To ge a mo e ealis ic
assessmen , we se up nginx o se e om a 571 MB co pus o 15,520 s a ic HTML
Wikipedia pages snapsho ed in 2006 [
137
]. File sizes a y om 417 by es o 522
KB (a e age size 37.7 KB). 75 keep-ali e clien s eques andom pages (selec ed
based on page iews on Wikipedia [
138
]). The a e age h oughpu wi h a single nginx
wo ke was 22,415 eques s/s in he base line and 21,802 eques s/s wi h ERIM (s d.
de s. below 0.6% in bo h cases). On a e age, he e we e 615,000 swi ches a second.
This co esponds o a o al o e head o 2.7%, o abou 0.43% o 100,000 swi ches a
second.
4.5.3.1 Scaling wi h mul iple wo ke s
To e i y ha ERIM scales wi h co e pa allelism, we e- an he i s expe imen abo e
wi h 3, 5 and 10 nginx wo ke s pinned o sepa a e co es, and su icien numbe s o
concu en clien s o sa u a e all he wo ke s. Table 4.7 shows he ela i e o e heads
wi h di e en numbe o wo ke s. Fo eques s la ge han hose shown in he able,
he ne wo k ca d sa u a es, and he spa e CPU cycles in he na i e base line abso b
ERIM’s o e head comple ely. Fo compa ison, he second and hi d columns o he
able epea he numbe s o he 1 wo ke con igu a ion o Table 4.6.
In he baseline, nginx’s h oughpu scales qui e well wi h he numbe o wo ke s.
Impo an ly, he ela i e o e head o ERIM’s p o ec ion does no inc ease wi h he
numbe o co es. Thus, ERIM scales wi h mul i-co e pa allelism indica ing ha
ERIM adds no addi ional synch oniza ion and scales pe ec ly wi h co e pa allelism.
99
File
size
(KB)
1 wo ke 3 wo ke s 5 wo ke s 10 wo ke s
Na i e
( e-
q/s)
ERIM
el.
(%)
Na i e
( e-
q/s)
ERIM
el.
(%)
Na i e
( e-
q/s)
ERIM
el.
(%)
Na i e
( e-
q/s)
ERIM
el.
(%)
0
95,761
95.83
276,736
96.05
466,419
95.67
823,471
96.40
1
87,022
95.18
250,565
94.50
421,656
96.08
746,278
95.47
2
82,137
95.44
235,820
95.12
388,926
96.60
497,778
100.00
4
76,562
95.25
217,602
94.91
263,719
100.00
8
67,855
95.98
142,680
100.00
Table 4.7:
Nginx h oughpu wi h mul iple wo ke s. The s anda d de ia ion is
below 1.5% in all cases.
This is unsu p ising gi en ha upda es o he PKRU o a co e a ec execu ion on
ha co e only.
4.5.3.2 Compa ison o ke nel-based isola ion
Using he single wo ke nginx expe imen , we compa e ERIM’s o e head o ha
o lwCs [
74
], a s a e-o - he-a sys em o in-p ocess isola ion based on s anda d
page- able p o ec ions. LwCs map each isola ed componen o a sepa a e add ess
space (in he same p ocess). A swi ch be ween componen s equi es ke nel media ion
o change page ables.
Since lwCs we e implemen ed only o F eeBSD, whose cu en ke nel suppo s
nei he MPKs no ou Xeon Gold machines, we un his compa ison expe imen
on an olde machine wi hou MPK suppo and use an emula ion o WRPKRU
o accoun o ERIM’s o e head as desc ibed in Sec ion 4.5.1.2. All expe imen s
desc ibed he e we e pe o med on Dell Op iPlex 7040 machines wi h 4-co e In el
Skylake i5-6500 CPUs clocked a 3.2GHz, 16GB memo y, 10 Gbps E he ne ca ds,
unning F eeBSD 11.
We use he exis ing single wo ke nginx expe imen (Sec ion 4.5.2) o compa e
he pe o mance o an ERIM-based isola ion o ha o lwC-based isola ion. As
opposed o ERIM swi ches, which ope a e en i ely in use space, lwC swi ches a e
syscalls. We c ea e a second ins ance o nginx ha uses an lwC (in place o an ERIM
100
componen ) o isola e session keys and basic c yp og aphic unc ions. We alloca e
da a bu e s in a memo y egion ha is sha ed be ween he p o ec ed lwC and he
web se e lwC o acili a e e icien da a sha ing. The o e head o WRPKRU is
emula ed as p e iously explained.
Figu e 4.4b depic s he o e head o he ERIM- and lwC-based a ian s ela i e
o he na i e baseline o an unmodi ied nginx, a e aged o e 20 uns. Nginx is
con igu ed o un one wo ke and se es 4 ApacheBench ins ances each simula ing
75 clien s accessing a s a ic ile ia HTTPS wi h keep-ali e.
The ERIM-based emula ion p o ides h oughpu wi hin 97.88% (wi hin 99%
o iles 64KB and la ge ) o he unp o ec ed na i e se e , whe eas he lwC-based
isola ion is limi ed o 50% o he na i e se e h oughpu o small iles and up o
80% o la ge (2MB) iles. The eason is he cos o lwC swi ch syscalls, which is oo
high gi en he a e o in oca ions o he enc yp ion unc ions.
Figu e 4.4a shows he absolu e numbe o se ed eques s pe second o he same
expe imen . The lwC-based nginx canno sus ain mo e han 26,500 eq/s, whe eas
ERIM pe o ms close o he na i e implemen a ion. A 64KB iles we sa u a e he
10Gbi ne wo k link esul ing in lowe eq/s o he na i e baseline and ERIM.
In summa y, we ind ha lwCs pe o m signi ican ly wo se han ERIM in his
expe imen : The h oughpu o nginx wi h lwC-based isola ion is ne e abo e 80%
o na i e nginx and, o small eques s, whe e he swi ch a e is highe , i is below
50% o na i e nginx. In con as , wi h ERIM’s isola ion, he h oughpu is wi hin
95% o na i e nginx in all con igu a ions. Hence, ERIM pe o ms signi ican ly be e
han ke nel-media ed isola ion a high swi ch a es.
4.5.4 Isola ing managed un imes
Nex , we es ERIM’s use o isola e a managed language un ime om an un us ed
na i e lib a y. Speci ically, we link he widely-used na i e da abase lib a y, SQLi e,
101

0
20000
40000
60000
80000
100000
0kb
1kb
2kb
4kb
8kb
16kb
32kb
64kb
128kb
256kb
512kb
1mb
2mb
Reques s/s
File size
Na i e
ERIM (emula ed)
LwC
(a) A e age numbe o eques s pe second, na i e, ERIM and lwC.
0
0.2
0.4
0.6
0.8
1
0kb
1kb
2kb
4kb
8kb
16kb
32kb
64kb
128kb
256kb
512kb
1mb
2mb
No malized Th oughpu
File size
Na i e
ERIM (emula ed)
LwC
(b) ERIM and lwC h oughpu no malized o na i e.
Figu e 4.4:
Nginx h oughpu wi h one wo ke , wi h emula ed ERIM p o ec ion
and wi h lwCs, wi h a ying eques sizes. S anda d de ia ions we e all below 1.1%.
102
o Node.js, a s a e-o - he-a Ja aSc ip un ime and use ERIM o isola e Node.js
om SQLi e by mapping Node.js’s un ime o
T
and he na i e lib a y o
U
. We
manually ins umen ed SQLi e’s en ypoin s o in oke call ga es. Addi ionally, since
we wan o isola e Node.js’s s ack om SQLi e, we un Node.js on a sepa a e s ack
in
MT
, and add code o swi ch o he s anda d s ack (in
MU
) p io o calling a
SQLi e unc ion. Finally, SQLi e uses he libc unc ion
memmo e
, which accesses libc
cons an s ha a e in
MT
, so we implemen ed a sepa a e
memmo e
o SQLi e. In
o al, we added 437 LoC.
We measu e un ime using he speed es 1 benchma k ha comes wi h SQLi e
and emula es a ypical da abase wo kload [
122
]. This benchma k pe o ms a o al o
32 sho es s ha s ess di e en da abase unc ions like selec s, joins, inse s and
dele es. We inc eased he i e a ions in each es by a ac o o ou o make he es s
longe . Ou base line o compa ison is anilla SQLi e linked o Node.js wi hou any
p o ec ion. We con igu e he benchma k o s o e he da abase in-memo y and epo
a e ages o 20 uns.
The geome ic mean o ERIM’s o e head on un ime ac oss all es s is 4.3%.
The o e head is below 6.7% on all es s excep hose wi h mo e han 10
6
swi ches
pe second. This sugges s ha ERIM can be used o isola ing na i e lib a ies om
managed language un imes wi h low o e heads up o a swi ching cos o he o de o
10
6
pe second. Beyond ha he o e head is no iceable. Table 4.8, columns 1–3, show
he ela i e o e heads o es s wi h swi ching a es o a leas 100,000/s. These a e
consis en wi h an a e age o e head be ween 0.07% and 0.41% o 100,000 swi ches/s.
The ac ual swi ch cos measu ed om di ec CPU cycle coun s a ies om 73 o 260
cycles ac oss all es s. The swi ch cos exceeds 100 cycles only on benchma ks whe e
he swi ch a e is e y low (less han 2,000 imes/s). We e i ied ha hese highe
cycle coun s a e due o ins uc ion cache misses—a e y low swi ch a es, he call
ga e is lushed ou o he ins uc ion cache be ween swi ches.
103
Tes
#Swi ches/s O e head (%)
ERIM WebAssembly
100 11,183,281 12.73% 132.48%
110 8,329,914 12.18% 135.44%
400 8,161,584 15.42% 156.04%
120 7,190,766 13.81% 145.19%
142 7,074,553 9.41% 165.88%
500 6,419,008 12.13% 119.15%
510 5,868,395 5.60% 113.76%
410 5,091,212 3.64% 122.77%
240 2,358,524 3.74% 126.63%
280 2,303,516 3.22% 100.05%
170 1,264,366 4.22% 104.87%
310 1,133,364 2.92% 81.71%
161 1,019,138 2.81% 138.64%
160 1,014,829 2.73% 136.27%
230 670,196 2.04% 193.42%
270 560,257 2.28% 92.78%
Table 4.8:
O e head ela i e o na i e execu ion o SQLi e speed es 1 es s wi h
mo e han 100,000 swi ches/s. S anda d de ia ions we e below 5.6% o na i e, and
ERIM and below 15.4% o WebAssembly.
4.5.4.1 Compa ison o isola ion wi h bounds checks (SFI)
We also use he abo e expe imen o compa e ERIM o isola ion based on bounds
checks. Fo his, we e-compile he SQLi e lib a y o na i e code indi ec ly h ough
WebAssembly, a new memo y-sa e, low-le el language designed speci ically o w i ing
sa e na i e plugins o Ja aSc ip en i onmen s [
53
]. The WebAssembly o na i e
code ansla ion inse s bounds checks p io o indi ec memo y accesses. Compila ion
ia WebAssembly is he cu en ly ecommended me hod o sa ely adding na i e
plugins o Google’s Ch ome web b owse ; mos majo web b owse s a e expec ed o
ecommend he same me hod in he nea u u e.
Ac oss all 32 es s, he geome ic mean o he ela i e o e head o WebAssembly-
based isola ion on un ime is 133.5%. The o e heads ange om 66.4% o 280.6%,
which is signi ican ly highe han ERIM’s o e heads. Howe e , WebAssembly’s
o e heads do no inc ease wi h he swi ching a e since i does no in e pose on
104
swi ches. Ins ead, i imposes a con inuous o e head while execu ion is in SQLi e.
O he wo k using bounds checks has ound simila ly high o e heads on pe o mance-
in ensi e benchma ks [95, 53].
4.6 Rela ed Wo k
Re e ence moni o s [
6
] media e p i ileged access by un us ed applica ions p o ec ing
da a con iden iali y and in eg i y, by sandboxing he applica ion o checks inse ed
in o he applica ions execu ion. All implemen a ions sha e he impo an p ope y
o p o ec ing he e e ence moni o ’s code and s a e om co up ion and deploy
isola ion echniques shielding he e e ence moni o . Leas -p i ilege and p i ilege
sepa a ion [
105
] de ine he basis o oday’s e e ence moni o mechanisms in ha dwa e
([
82
,
63
,
12
]), hype iso s ([
14
,
19
]), ope a ing sys ems ([
132
,
35
]) o applica ions
([
129
,
80
,
41
,
143
,
29
]). Two ecen su eys [
126
,
117
] show iable a acks and possible
coun e measu es o p o ec agains da a con iden iali y and in eg i y iola ions.
Fu he mo e hei in e cep ion g anula i y a ies om a sepa a e gues OS ([
14
]),
a single applica ion ([
19
,
20
,
132
]) o applica ion componen s ([
129
,
82
,
74
,
80
,
41
,
143
,
29
,
144
]). In e cep ing a ine g anula i y o e s isola ion ac oss applica ion
componen s, whe eas cou se-g ain in e cep ion isola es independen applica ions o
componen s. Due o i s equen in oca ions, ine-g ained in e cep ion solu ions
equi e isola ion echniques wi h low o e head. ERIM isola es applica ion componen s
and in e cep s ine-g ained secu i y ele an e en s wi hin he applica ion, simila ly
o ARMlock [
144
] o SFI-based isola ion [
129
,
80
,
41
,
143
]. This is in con as o
echniques using OS p ocess bounda ies ([74]) o CPU p i ilege le els ([19, 14]).
Koning e al. [
68
] su ey echniques o e icien da a encapsula ion wi hin a
p ocess, including SFI, dynamic enc yp ion o p i a e da a using he In el AES-NI
ISA ex ensions, app oaches ha use VT-x i ualiza ion ha dwa e, and hose ha
ely on he In el MPX and MPK ISA ex ensions. I hen p esen s a gene al isola ion
105

CHAPTER 5
Conclusion
Today compu e s s o e and analyze aluable and sensi i e da a such as pe sonal
mul imedia o clien eco ds. An impo an goal is o p o ec he con iden iali y
and in eg i y o such da a, minimizing he isk o illici elease, loss o modi ica ion.
Howe e , exis ing echniques o p o ec con iden iali y and in eg i y a e ulne able
o malicious a acks o a e ine icien . This hesis con ibu es wo new echniques,
Gua da and ERIM, p o iding con iden iali y and in eg i y o pe sis en and in-
memo y da a secu ely and e icien ly.
Gua da en o ces, a he s o age laye , ich pe - ile con iden iali y and in eg i y
policies wi h low o e head. The en o cemen a he s o age laye educes he a ack
su ace and he isk o ci cum en ion due o so wa e bugs, miscon igu a ions and
ope a o e o s in highe laye s. Gua da o e comes he gap be ween s o age laye
en o cemen and pe - ile policies by a es ing he s a e o iles and associa ed policies
h ough c yp og aphically-signed ce i ica es. To speci y policies, we de elop a
domain-speci ic language which allows da a accesses condi ioned on au hen ica ion,
us ed wall clock ime, and a ile’s s a e including he con en . We demons a e an
e icien implemen a ion o en o ce such policies in an iSCSI SAN se e and apply
Gua da o wo use cases p o ec ing he con en , execu able, and log iles o a web
se e , as well as en o cing manda o y access logging.
ERIM p o ides da a con iden iali y and in eg i y o in-memo y da a by isola ing
sensi i e da a om accesses by un us ed componen s. I isola es sensi i e da a
113
in o a sepa a e, us ed memo y componen using In el MPK and ensu es ha
only he us ed componen has access o sensi i e da a. To p e en malicious
a acks om escala ing p i ileges using he unp i ileged WRPKRU CPU ins uc ion,
ERIM addi ionally p o ec s he us ed componen ia secu e con ol ans e s and
bina y inspec ion. Secu e con ol ans e s ensu e ha he un us ed componen
canno ele a e access pe missions wi hou he in ol emen o he us ed componen .
Bina y inspec ion gua an ees ha no execu able bina y code sequence ele a es access
pe missions o he us ed componen , while execu ing un us ed code. ERIM’s
isola ion imposes no addi ional o e head on he execu ion and less han 1% un ime
o e head pe 100,000 swi ches/second. Unlike s a e-o - he-a isola ion echniques,
he low swi ch cos and no o e head on execu ion allows ERIM o e icien ly isola e
equen ly-used session keys in web se e s, an in-memo y e e ence moni o ’s p i a e
s a e, and managed un imes om na i e lib a ies as demons a ed in he e alua ion.
5.1 Fu u e Wo k
Gua da and ERIM independen ly p o ec he con iden iali y and in eg i y o sensi i e
pe sis en and in-memo y da a. While Gua da es ic s da a accesses a he s o age
laye , i does no p o ec da a eleased o an applica ion. In con as ERIM es ic s
access o applica ion da a, bu does no p o ec pe sis en da a om malicious
a acks. Al hough beyond he goal o his hesis, in his sec ion we discuss how o
o e come he limi a ions o each echnique and a ain an end- o-end con iden iali y
and in eg i y gua an y o sensi i e pe sis en da a h oughou i s in-memo y use in
an applica ion.
We can o e come he limi a ions o each indi idual sys em by connec ing an
ERIM-isola ed moni o o a Gua da de ice which s o es he sec e s. These pe sis-
en ly s o ed sec e s on a Gua da de ice could be p o ec ed om a bi a y da a
accesses by associa ing a policy which allows da a access only by au ho ized connec-
114
ions. Howe e , wi hou any changes o ERIM, an ERIM-isola ed moni o would
no be able o access hese sec e s. To gain access, he moni o has o connec o
he Gua da de ice and au hen ica e i sel . The cu en design o ERIM does no
p o ide a way o gene a e a unique au ho iza ion sec e ha is eliable and consis en
ac oss en i onmen s and eboo s. In o de o gene a e au ho iza ion sec e s, exis ing
echniques like us ed pla o m modules (TPM) o In el SGX gene a e au ho iza ion
sec e s o code by measu ing he code’s in-memo y oo p in as a secu e hash. This
hash is hen used o de i e a unique au ho iza ion sec e .
Simila o exis ing echniques, we sugges o change ERIM’s ini ializa ion o
gene a e an au ho iza ion sec e by measu ing he us ed moni o ’s oo p in . Once
measu ed, he sec e is placed in he us ed moni o ’s memo y (ou side o he
un us ed applica ion’s each). Using his sec e , he us ed moni o au hen ica es
i sel o he Gua da de ice. This app oach gua an ees ha Gua da only eleases
sec e s o an ERIM-isola ed moni o , while ERIM p o ec s he in-memo y copy o
he sec e om accesses by an un us ed applica ion.
By connec ing an ERIM-isola ed moni o o Gua da we p o ide an end- o-end
con iden iali y and in eg i y gua an ee which would be pa icula ly in e es ing o
se e applica ions ha ely on a secu e connec ion o clien s using asymme ic
c yp og aphy. In oday’s se e and c yp og aphic lib a y implemen a ions (see
Figu e 5.1a) he p i a e and session keys a e no isola ed in memo y o p o ec ed in
pe sis en s o age. Exis ing se e applica ions ead a p i a e key om pe sis en
s o age in o memo y and use he key o es ablish a secu e connec ion by nego ia ing
a session key. The session key is s o ed in memo y and used by bo h pa ies o
enc yp and dec yp messages. Hence, secu i y ulne abili ies and bugs in he
un us ed se e applica ion, he ope a ing sys em, o applica ions wi h access o
he s o age may esul in a con iden iali y o in eg i y iola ion. Fo example,
unau ho ized applica ions may ead he pe sis en p i a e key and elease hem,
iola ing con iden iali y. Simila ly, he key could be modi ied on disk, iola ing
115
(a)
Today’s se e applica-
ions
(b)
Isola ing a c yp o-
g aphic lib a y using ERIM
and connec ing i o a Gua -
da de ice
(c)
Combining ERIMwi h
So wa e Gua d Ex ensions
(SGX) o isola e om he
ope a ing sys em
Figu e 5.1: S eps owa ds an isola ed c yp og aphic lib a y in se e applica ions
in eg i y. Once he keys eside in memo y, malicious a acks like Hea bleed [
90
] can
elease o modi y he keys, iola ing bo h con iden iali y and in eg i y.
To p o ec he keys om hese ypes o h ea s, Gua da in combina ion wi h
ERIM can p o ec he pe sis en keys and he in-memo y keys e icien ly as shown in
Figu e 5.1b. The se e needs o be spli in o a us ed moni o which only holds he
c yp og aphic unc ions and an un us ed se e which handles he communica ion
and p o ides he se ice o he clien . Du ing ini ializa ion ERIM isola es he us ed
moni o ’s memo y om he un us ed se e applica ion. ERIM measu es he us ed
moni o and p o ides he au ho iza ion sec e o he us ed moni o . I hen allows
he us ed moni o o ini ialize, connec o a Gua da de ice, au ho ize using he
p e iously measu ed sec e , and ead he p i a e key. Gua da checks ha he
au hen ica ed clien ac ually is he ERIM-isola ed us ed moni o which is speci ied
in he policy. A e inishing he us ed moni o ’s ini ializa ion, ERIM s a s he
un us ed se e , which begins i s usual ope a ion wai ing o clien s o connec .
Once a clien connec s o es ablish a secu e connec ion, he un us ed se e accep s
he connec ion, s a s he SSL/TLS handshake p o ocol and swi ches o he us ed
moni o whene e enc yp ing o dec yp ing messages using he in-memo y p i a e
key and gene a ing new session keys.
116
In con as o he h ea model o Gua da which assumes in e media e laye s,
such as he OS, o be ulne able o malicious a acks o ci cum en ion, he echnique
p oposed abo e, howe e , assumes he OS o be us ed, since ERIM’s gua an ees
depend on he OS. As a esul , he p oposed solu ion would only p o ec con iden iali y
and in eg i y agains a acks om ou side, e.g., malicious clien s a acking he se e
like Hea bleed [
90
], and any h ea s on he ne wo k be ween he machine unning
he se e and he Gua da de ice. Such a h ea model is common o se e s
unning in he cloud.
Fu he ha dening ERIM agains OS ulne abili ies:
While he cloud h ea
model is commonly assumed, ecen a acks [
24
] show how o he cloud enan s
can access in-memo y sec e s iola ing con iden iali y and in eg i y. In addi ion,
highly sensi i e applica ions may no assume he cloud p o ide o be us ed and,
hence, in e media e laye s like he OS and VMM which p o ide isola ion a e no
longe us ed. In o de o s eng hen he h ea model o he p esen ed echnique,
he memo y isola ion gua an ees o ERIM ha e o be independen o in e media e
so wa e laye s like he OS o VMM.
To de end agains hese h ea s, us ed execu ion en i onmen s (TEE), in
pa icula In el SGX, can be used o shield sensi i e da a om he cloud pla o m
and o he enan s. SGX p o ides in-memo y encla es o s o e sensi i e da a and
execu e code independen o he unning OS o VMM. Se e al esea ch sys ems
[
17
,
13
,
70
] demons a e he use o In el SGX o shield an applica ion agains he
cloud pla o m.
While SGX p o ides s ong memo y isola ion gua an ees, i s high swi ch cos s
compa able o a con ex swi ch hinde s i s adop ion, and p e en s i om being
used o isola e equen ly-used sec e s. Exis ing wo k o e comes hese pe o mance
limi a ions by ei he isola ing in equen ly-used sec e s like p i a e keys o isola ing
an en i e applica ion. Howe e , pushing en i e applica ions (e.g., a se e ) in o
117

an encla e wi hou u he memo y isola ion lea es he applica ion ulne able o
malicious a acks, due o he size and complexi y o hese applica ions. Recen
wo k [
71
] sugges s u he p o ec ing applica ions in SGX encla es by adding memo y
bound checks. Howe e , such checks incu subs an ial un ime o e head, and i is
no su icien o ERIM o simply swap In el MPK o In el SGX. Ins ead, we need
o combine bo h app oaches o allow en i e applica ions o un wi hin SGX encla es,
shielding hem om he emaining cloud so wa e s ack, while isola ing sec e s wi hin
he applica ion using a mechanism simila o In el MPK.
To his end, we sugges amending he SGX speci ica ion, since i has no p o ision
o MPK-like memo y isola ion using pe -page domains and an access pe mission
egis e such as he PKRU egis e . The encla e memo y desc ip o s eside in
p ocesso ese ed memo y which is inaccessible o sys em so wa e (e.g., OS o
VMM). An impo an desc ip o is he encla e page cache map (EPCM), a able-like
s uc u e, which holds in o ma ion abou which memo y pages belongs o an encla e
and holds pe -page access pe mission bi s. Cu en ly he EPCM allows pages o be
accessible wi h ead, w i e, and execu e pe mission and does no allow pages o be
agged wi h a MPK domain.
To allow page-le el memo y isola ion wi hin SGX encla es, we sugges adding
memo y domain iden i ie s o he EPCM and ex ending he CPU’s memo y access
pe mission check o alida e he cu en access pe missions in he PKRU egis e
agains he memo y access’s EPCM domain iden i ie . This app oach ex ends he
each o In el MPK in o SGX encla es. Simila o he use o MPK in ERIM, his
solu ion is ulne able o malicious a acks and hence needs o be combined wi h
ERIM’s secu e con ol ans e s and bina y inspec ion. Fo code in encla es, we can
simpli y ERIM’s bina y inspec ion, since encla e memo y is alloca ed once a he
s a o an encla e and can only be ex ended wi h a special p o ocol including a s ep
in which he encla e app o es he ex ension [
83
]. The bina y inspec ion could scan
once a he s a o unsa e WRPKRUs in all execu able memo y and a un ime i
118
could only app o e new pages which do no con ain unsa e WRPKRUs. The e is no
need o ke nel modi ica ions o signal handle s. By amending he SGX speci ica ion
and combining i wi h ERIM’s secu e con ol ans e s and bina y inspec ion, we
can isola e equen ly-used sec e s wi hin SGX encla e wi hou us ing he sys em
so wa e like he OS (see Figu e 5.1c).
In his sec ion we ha e shown how o ex end he p o ec ion o pe sis en iles om
Gua da o in-memo y da a using ERIM. We discussed he challenge in au hen ica ing
an ERIM-isola ed us ed moni o o a Gua da de ice and desc ibe a echnique
o gene a e an au hen ica ion sec e using code measu emen s. We discuss i s use
in a commonly assumed h ea model o cloud en i onmen s. Fo highly sensi i e
applica ions, we desc ibe an ex ension o In el’s SGX o p o ec agains ogue cloud
p o ide s and o he cloud enan s.
119
Bibliog aphy
[1]
Ma ín Abadi, Mihai Budiu, Úl a E lingsson, and Jay Liga i. Con ol- low
in eg i y. In P oceedings o ACM SIGSAC Con e ence on Compu e and
Communica ions Secu i y (CCS), 2005.
[2]
Ni in Ag awal, William J. Bolosky, John R. Douceu , and Jacob R. Lo ch. A
i e-yea s udy o ile-sys em me ada a. ACM T ansac ions on S o age, 3(3),
2007.
[3]
Ma cos K. Aguile a, Minwen Ji, Ma k Lillib idge, John MacCo mick, E win
Oe li, Da id G. Ande sen, Mike Bu ows, Timo hy Mann, and Chand amohan
Thekka h. Block-Le el Secu i y o Ne wo k-A ached Disks. In P oceedings
o USENIX Con e ence o File and S o age Technologies (FAST), 2003.
[4]
Hussain M. J. Almoh i and Da id E ans. Fidelius Cha m: Isola ing Unsa e
Rus Code. In P oceedings o ACM Con e ence on Da a and Applica ion
Secu i y and P i acy (CODASPY), 2018.
[5]
Amazon. Amazon Simple S o age Se ice (Amazon S3).
h p://aws.amazon.
com/s3/, 2011.
[6] James P. Ande son. Compu e Secu i y Technology Planning S udy (Volume
II), 1972.
[7]
Jason Ansel, Pe Ma chenko, Ul a E lingsson, Elijah Taylo , B ad Chen,
De ek L. Schu , Da id Seh , Cli L. Bi le, and Benne Yee. Language-
independen sandboxing o jus -in- ime compila ion and sel -modi ying code.
In P oceedings o ACM SIGPLAN con e ence on P og amming language design
and implemen a ion (PLDI), 2011.
120
[8]
Apache HTTP Se e P ojec .
h ps://h pd.apache.o g/docs/2.4/
p og ams/ab.h ml.
[9] Apple Inc. Time Machine, 2007.
[10] Apple Inc. Apple Fusion D i e. h ps://www.apple.com/de/imac, 2017.
[11]
ARM. De elope guide: ARM memo y domains.
h p://in ocen e .a m.
com/help/, 2001.
[12]
ARM. ARM Secu i y Technology.
h p://in ocen e .a m.com/
help/ opic/com.a m.doc.p d29-genc-009492c/PRD29-GENC-009492C_
us zone_secu i y_whi epape .pd , 2009.
[13]
Se gei A nau o , Bohdan T ach, F anz G ego , Thomas Knau h, And e Ma in,
Ch is ian P iebe, Joshua Lind, Di ya Mu hukuma an, Ma k L. S illwell, Da id
Gol zsche, Da id Eye s, Pe e Pie zuch, and Ch is o Fe ze . SCONE: Secu e
Linux Con aine s wi h In el SGX. In P oceedings o USENIX Symposium on
Ope a ing Sys ems Design and Implemen a ion (OSDI), 2016.
[14]
Paul Ba ham, Bo is D ago ic, Kei F ase , S e en Hand, Tim Ha is, Alex
Ho, Rol Neugebaue , Ian P a , and And ew Wa ield. Xen and he a o
i ualiza ion. ACM SIGOPS Ope a ing Sys ems Re iew, 37(5), 2003.
[15]
F i zge ald Ba h, Vic o Chin, Moshe Fe be , Sean Hi el, Lau ie Jame-
son, Na heniel Mason, Ha deep Meh o a a, Ashish Meh a, Mihi Mohan y,
K ishna Na ayanswamy, and Michael Roza. Top h ea s o cloud compu ing
plus indus y insigh s.
h ps://www.couldsecu i yaliance.o g/download/
op- h ea s- o-cloud-compu ing-plus-indus y-insigh s/, 2017.
[16]
E ick Bauman, Zhiqiang Lin, and Ke in W. Hamlen. Supe se disassembly:
S a ically ew i ing x86 bina ies wi hou heu is ics. In P oceedings o Ne wo k
and Dis ibu ed Sys ems Secu i y Symposium (NDSS), 2018.
121
[65]
The iSCSI En e p ise Ta ge P ojec .
h p://iscsi a ge .sou ce o ge.
ne /, 2011.
[66]
T. Jim. SD3: A us managemen sys em wi h ce i ied e alua ion. In
P oceedings o IEEE Compu e Socie y Symposium on Resea ch in Secu i y
and P i acy, 2001.
[67]
Douglas Kilpa ick. P i man: A Lib a y o Pa i ioning Applica ions. In
P oceedings o USENIX Anual Technical Con e ence (ATC), 2003.
[68]
Koen Koning, Xi Chen, He be Bos, C is iano Giu ida, and Elias A hana-
sopoulos. No Need o Hide: P o ec ing Sa e Regions on Commodi y Ha dwa e.
In P oceedings o ACM Eu opean Con e ence on Compu e Sys ems (Eu oSys),
2017.
[69]
Ramak ishna Ko la, Tom Rodehe e , Ind aji Roy, Pa ick S uedi, and Ben-
jamin Wes e . Pas u e: Secu e O line Da a Access using Commodi y T us ed
Ha dwa e. In P oceedings o USENIX Symposium on Ope a ing Sys ems Design
and Implemen a ion (OSDI), 2012.
[70]
Robe K ahn, Bohdan T ach, Anjo Vahldiek-Obe wagne , Thomas Knau h,
P amod Bha o ia, and Ch is o Fe ze . Pesos: Policy Enhanced Secu e Objec
s o e. In P oceedings o ACM Eu opean Con e ence on Compu e Sys ems
(Eu oSys), 2018.
[71]
Dmi ii Ku aiskii, Oleksii Oleksenko, Se gei A nau o , Bohdan T ach, P amod
Bha o ia, Pascal Felbe , and Ch is o Fe ze . SGXBOUNDS: Memo y Sa e y o
Shielded Execu ion. In P oceedings o ACM Eu opean Con e ence on Compu e
Sys ems (Eu oSys), 2017.
128

[72]
Volodymy Kuzne so , László Szeke es, and Ma hias Paye . Code-poin e
in eg i y. In P oceedings o USENIX Symposium on Ope a ing Sys ems Design
and Implemen a ion (OSDI), 2014.
[73]
Ninghui Li and John C. Mi chell. Da alog wi h Cons ain s: A Founda ion o
T us Managemen Languages. In P oceedings o ACM Symposium on P ac ical
Aspec s o Decla a i e Languages (PADL), 2003.
[74]
James Li on, Anjo Vahldiek-Obe wagne , Eslam Elnike y, Deepak Ga g,
Bobby Bha acha jee, and Pe e D uschel. Ligh -Weigh Con ex s: An OS
Abs ac ion o Sa e y and Pe o mance. In P oceedings o USENIX Symposium
on Ope a ing Sys ems Design and Implemen a ion (OSDI), 2016.
[75]
Yu ao Liu, Tianyu Zhou, Kexin Chen, Haibo Chen, and Yubin Xia. Thwa ing
Memo y Disclosu e wi h E icien Hype iso -en o ced In a-domain Isola ion.
In P oceedings o ACM SIGSAC Con e ence on Compu e and Communica ions
Secu i y (CCS), 2015.
[76]
Boon Thau Loo. The Design and Implemen a ion o Decla a i e Ne wo ks.
PhD hesis, Uni e si y o Cali o nia, Be keley, 2006.
[77]
Boon Thau Loo, Tyson Condie, Joseph M. Helle s ein, Pe os Mania is, Timo-
hy Roscoe, Ion S oica, Thau Loo, Pe os Mania is, Tyson Condie, Timo hy
Roscoe, and Joseph M. Helle s ein. Implemen ing decla a i e o e lays. In
ACM SIGOPS Ope a ing Sys ems Re iew, olume 39, 2005.
[78]
Kangjie Lu, Chengyu Song, Byoungyoung Lee, Simon P. Chung, Taesoo Kim,
and Wenke Lee. ASLR-Gua d: S opping Add ess Space Leakage o Code
Reuse A acks. In P oceedings o ACM SIGSAC Con e ence on Compu e and
Communica ions Secu i y (CCS), 2015.
129
[79]
Michelle L. Mazu ek, Yuan Liang, William Meliche , Manya Sleepe , Lujo
Baue , G ego y R. Gange , Ni in Gup a, and Michael K. Rei e . Towa d s ong,
usable access con ol o sha ed dis ibu ed da a. In P oceedings o USENIX
Con e ence on File and S o age Technologies (FAST), 2014.
[80]
S ephen Mccaman and G eg Mo ise . E alua ing SFI o a CISC A chi ec u e.
In P oceedings o USENIX Secu i y Symposium, 2006.
[81]
Jona han M. McCune, Yanlin Li, Ning Qu, Zongwei Zhou, Anupam Da a,
Vi gil Gligo , and Ad ian Pe ig. T us iso : E icien cb educ ion and
a es a ion. In P oceedings o IEEE Symposium on Secu i y and P i acy
(Oakland), 2010.
[82]
Jona han M. McCune, B yan J. Pa no, Ad ian Pe ig, Michael K. Rei e , and
Hi oshi Isozaki. Flicke : An Execu ion In as uc u e o TCB Minimiza ion.
In P oceedings o ACM Eu opean Con e ence on Compu e Sys ems (Eu oSys),
2008.
[83]
F ank McKeen, Ilya Alexand o ich, I ai Ana i, D o Caspi, Simon Johnson,
Rebekah Leslie-Hu d, and Ca los Rozas. In el so wa e gua d ex ensions
suppo o dynamic memo y managemen inside an encla e. In P oceedings o
Ha dwa e and A chi ec u al Suppo o Secu i y and P i acy, 2016.
[84]
Aas ha Meh a, Eslam Elnike y, Ka u a Ha ey, Deepak Ga g, and Pe e
D uschel. Qapla: Policy compliance o da abase-backed sys ems. In P oceedings
o USENIX Secu i y Symposium, 2017.
[85]
Michael Mesnie , Feng Chen, Tian Luo, and Jason B. Ake s. Di e en ia ed
s o age se ices. In P oceedings o ACM Symposium on Ope a ing Sys ems
P inciples (SOSP), 2011.
130
[86]
Mike Mesnie , G ego y R. Gange , and E ik Riedel. Objec -based s o age.
IEEE Communica ions Magazine, 41(8), 2003.
[87]
Mic oso Co p. Bi locke .
h ps://docs.mic oso .com/en-us/windows/
secu i y/in o ma ion-p o ec ion/bi locke /bi locke -o e iew.
[88]
Mic oso Co p. Windows Backup and Res o e.
h p://www.mic oso .com/
a home/se up/backupda a.aspx{#} bid=l7X90d97alI.
[89]
Mic oso Co p. Wha Is Volume Shadow Copy Se ice?: Da a Re-
co e y.
h ps:// echne .mic oso .com/en-us/lib a y/cc757854( =ws.
10).aspx, 2003.
[90]
MITRE. CVE-2014-0160.
h ps://n d.nis .go / uln/de ail/
CVE-2014-0160, 2014.
[91] Node.js Founda ion. h ps://nodejs.o g.
[92] Oasis. eX ensible Access Con ol Ma kup Language, 2005.
[93]
OCZ Technology Inc. Dene a 2 Da a Shee .
h ps://d i e.google.com/
ile/d/0B4hWjkpwenosS0VMOWZkZ1B R1E/ iew?usp=sha ing, 2011.
[94]
Angelos Oikonomopoulos, Elias A hanasopoulos, He be Bos, and C is iano
Giu ida. Poking Holes in In o ma ion Hiding. In P oceedings o USENIX
Secu i y Symposium, 2016.
[95]
Oleksii Oleksenko, Dmi ii Ku aiskii, P amod Bha o ia, Pascal Felbe , and
Ch is o Fe ze . In el MPX Explained: A C oss-laye Analysis o he In el
MPX Sys em S ack. In P oceedings o ACM on Measu emen and Analysis o
Compu ing Sys ems, 2018.
[96]
OpenSSL. C yp o (OpenSSL c yp og aphic lib a y).
h p://www.openssl.
o g/, 2012.
131
[97]
B yan Pa no, Jona han M. McCune, and Ad ian Pe ig. Boo s apping T us
in Mode n Compu e s. In P oceedings o IEEE Symposium on Secu i y and
P i acy (Oakland), 2011.
[98]
Da id A. Pa e son, Ga h Gibson, and Randy H. Ka z. A case o edun-
dan a ays o inexpensi e disks (RAID). In P oceedings o ACM SIGMOD
in e na ional con e ence on Managemen o da a (SIGMOD), 1988.
[99]
Adam G. Penning on, John Linwood G i in, John S. Bucy, John D. S unk,
and G ego y R. Gange . S o age-Based In usion De ec ion. ACM T ansac ions
on In o ma ion and Sys em Secu i y, 13(4), 2010.
[100]
And ew Pimlo and Oleg Kiselyo . Sou ei, a Logic-Based T us -Managemen
Sys em. In P oceedings o In e na ional Symposium on Func ional and Logic
P og amming (FLOPS), 2006.
[101]
Sean Quinlan and Sean Do wa d. Ven i: a new app oach o a chi al da a
s o age. In P oceedings o USENIX Con e ence o File and S o age Technologies
(FAST), 2002.
[102]
E ik Riedel, Ch is os Falou os, Ga h a Gibson, and Da id Nagle. Ac i e Disks
o La ge Scale Da a P ocessing. Tc, 34(6), 2001.
[103] Rus language. h ps://www. us -lang.o g/.
[104]
Cai lin Sadowski, Edwa d A andilian, Alex Eagle, Liam Mille -Cushon, and
Cie a Jaspan. Lessons om building s a ic analysis ools a google. Commun.
ACM, 61(4):58–66, Ma ch 2018.
[105]
Je ome H. Sal ze and Michael D. Sch oede . The P o ec ion o In o ma ion
in Compu e Sys ems. In P oceedings o he IEEE, olume 63, 1975.
[106]
Samsung. 830 SSD da a shee .
h p://www.samsung.com/us/sys em/
consume /p oduc /mz/7p/c1/mz7pc128nam/830.pd , 2011.
132
[107]
Nuno San os, Rod igo Rod igues, K ishna P. Gummadi, and S e an Sa oiu.
Policy-sealed da a: A new abs ac ion o building us ed cloud se ices. In
P oceedings o USENIX Secu i y Symposium, 2012.
[108]
F ed B. Schneide , Ke in Walsh, and Emin Gün Si e . Nexus au ho iza ion logic
(NAL): Design a ionale and applica ions. ACM T ansac ions on In o ma ion
and Sys em Secu i y, 14(1), 2011.
[109]
Seaga e Technology LLC. Kine ic Open S o age Pla o m.
h p://www.
seaga e.com/solu ions/cloud/da a-cen e -cloud/pla o ms.
[110]
Seaga e Technology LLC. Sel -Enc yp ing Ha d Disk D i es in he Da a Cen e .
Technical Repo TP583, 2007.
[111]
Seaga e Technology LLC. Ba acuda Da a Shee .
h p://www.seaga e.com/
iles/s a ic iles/docs/pd /da ashee /disc/ba acuda-x -ds1696.
3-1102us.pd , 2012.
[112]
Seaga e Technology LLC. Momen us XT Da a Shee .
h p://www.seaga e.
com/docs/pd /da ashee /disc/ds_momen us_x .pd , 2012.
[113]
Ho a Shacham, Ma hew Page, Ben P a , Eu-Jin Goh, Nagend a Modadugu,
and Dan Boneh. On he e ec i eness o add ess-space andomiza ion. In
P oceedings o ACM SIGSAC Con e ence on Compu e and Communica ions
Secu i y (CCS), 2004.
[114]
Moni ul I. Sha i , Wenke Lee, Weidong Cui, and And ea Lanzi. Secu e in- m
moni o ing using ha dwa e i ualiza ion. In P oceedings o ACM SIGSAC
Con e ence on Compu e and Communica ions Secu i y (CCS), 2009.
[115]
Lei Shi, Yuming Wu, Yubin Xia, Na han Dau enhahn, Haibo Chen, Binyu
Zang, Haibing Guan, and Jiñming Li. Decons uc ing xen. In P oceedings o
Ne wo k and Dis ibu ed Sys em Secu i y Symposium (NDSS), 2017.
133

[116]
Jiwu Shu, Zhi ong Shen, and Wei Xue. Shield: A s ackable secu e s o age
sys em o ile sha ing in public s o age. J. Pa allel Dis ib. Compu ., 74(9),
Sep embe 2014.
[117]
Rui Shu, Peipei Wang, Sigmund A. Go ski III, Benjamin Andow, Adwai
Nadka ni, Luke Desho els, Jason Gion a, William Enck, and Xiaohui Gu. A
S udy o Secu i y Isola ion Techniques. ACM Compu ing Su eys, 49(3), 2016.
[118]
Emin Gün Si e , Willem de B uijn, Pa ick Reynolds, Alan Shieh, Ke in Walsh,
Dan Williams, and F ed B. Schneide . Logical a es a ion: an au ho iza ion
a chi ec u e o us wo hy compu ing. In P oceedings o ACM Symposium
on Ope a ing Sys ems P inciples (SOSP), 2011.
[119]
Gopalan Si a hanu, Swamina han Sunda a aman, and E ez Zadok. Type-sa e
disks. In P oceedings o USENIX Symposium on Ope a ing Sys ems Design
and Implemen a ion (OSDI), 2006.
[120]
Mu hian Si a hanu, Vijayan P abhaka an, Flo en ina I. Popo ici, Timo hy E.
Denehy, And e A paci-Dusseau, and Remzi A paci-Dusseau. Seman ically-
Sma Disk Sys ems. In P oceedings o USENIX Con e ence o File and S o age
Technologies (FAST), 2003.
[121] SQLi e. h ps://www.sqli e.o g.
[122] SQLi e. Speed es 1. h ps://www.sqli e.o g/ es ing.h ml.
[123]
S o age Wo k G oup o he T us ed Compu ing G oup. Sel -Enc yp ing D i es
Take o o S ong Da a P o ec ion.
h ps:// us edcompu ingg oup.o g/
sel -enc yp ing-d i es- ake-o -s ong-da a-p o ec ion/, 2010.
[124]
John D. S unk, Ga h R. Goodson, Michael L. Scheinhol z, C aig A. N.
Soules, and G ego y R. Gange . Sel -Secu ing S o age: P o ec ing Da a in
134
Comp omised Sys ems. In P oceedings o USENIX Symposium on Ope a ing
Sys ems Design and Implemen a ion (OSDI), 2000.
[125] Sun Mic osys ems. Sola is ZFS, 2009.
[126]
Laszlo Szeke es, Ma hias Paye , Tao Wei, and Dawn Song. SoK: E e nal
wa in memo y. In P oceedings o IEEE Symposium on Secu i y and P i acy
(Oakland), 2013.
[127]
TCG. TCG S o age A chi ec u e Co e Spec-
i ica ion.
h ps:// us edcompu ingg oup.o g/
cg-s o age-a chi ec u e-co e-speci ica ion/, 2007.
[128]
Eno The eska, Hi esh Ballani, G eg O’Shea, Thomas Ka agiannis, An Row-
s on, Tom Talepy, Richa d Black, and Timo hy Zhu. Io low: A so wa e-de ined
s o age a chi ec u e. In P oceedings o ACM Symposium on Ope a ing Sys ems
P inciples (SOSP), 2013.
[129]
Robe Wahbe, S e en Lucco, Thomas E. Ande son, and Susan L. G aham.
E icien so wa e-based aul isola ion. In P oceedings o ACM Symposium on
Ope a ing Sys ems P inciples (SOSP), 1993.
[130]
Ke in Walsh and F ed B. Schneide . Cos s o Secu i y in he PFS File Sys em.
Technical epo , Compu ing and In o ma ion Science, Co nell Uni e si y, 2012.
[131]
Da id H.D. Wa en. an Abs ac P olog Ins uc ion Se . Technical Repo
Technical No e 309, SRI In e na ional, 1983.
[132]
Robe N. M. Wa son, Jona han Ande son, Ben Lau ie, and K is Kennaway.
A as e o Capsicum. Communica ions o he ACM, 55(3), 2012.
[133]
Ca s en Weinhold and He mann Hä ig. VPFS: Building a i ual p i a e
ile sys em wi h a small us ed compu ing base. In ACM SIGOPS Ope a ing
Sys ems Re iew, 2008.
135
[134]
Ca s en Weinhold and He mann Hä ig. jVPFS: Adding Robus ness o a
Secu e S acked File Sys em wi h Un us ed Local S o age Componen s. In
P oceedings o USENIX Anual Technical Con e ence (ATC), 2011.
[135]
Jan We ne , Geo ge Bal as, Rob Dalla a, Na han O e ness, Ke in Z. Snow,
Fabian Mon ose, and Michalis Polych onakis. No-Execu e-A e -Read: P e-
en ing Code Disclosu e in Commodi y So wa e. In P oceedings o ACM
SIGSAC Asia Con e ence on Compu e and Communica ions Secu i y (Asia
CCS), 2016.
[136]
Wikimedia Founda ion. Image Dump.
h p://a chi e.o g/de ails/
wikimedia-image-dump-2005-11, 2005.
[137]
Wikimedia Founda ion. S a ic HTML dump.
h p://dumps.wikimedia.o g/
,
2008.
[138]
Wikimedia Founda ion. Page iew s a is ics Ap il 2012.
h p://dumps.
wikimedia.o g/o he /pagecoun s- aw/2012/2012-04/, 2012.
[139]
Edwa d Wobbe , Ma ín Abadi, Michael Bu ows, and Bu le Lampson. Au-
hen ica ion in he Taos ope a ing sys em. ACM T ansac ions on Compu e
Sys ems, 12(1), 1994.
[140]
Ted Wobbe , Aydan Yume e endi, Ma ín Abadi, And ew Bi ell, and Daniel R.
Simon. Au ho izing applica ions in singula i y. In ACM SIGOPS Ope a ing
Sys ems Re iew, olume 41, 2007.
[141]
Rubin Xu, Hassen Saïdi, and Ross Ande son. Au asium: P ac ical Policy
En o cemen o And oid Applica ions. In P oceedings o USENIX Secu i y
Symposium, 2012.
136
[142]
Yuanzhong Xu, Alan M. Dunn, Owen S. Ho mann, Michael Z. Lee, Syed Akba
Mehdi, and Emme Wi chel. Applica ion-de ined decen alized access con ol.
In P oceedings o USENIX Anual Technical Con e ence (ATC), 2014.
[143]
Benne Yee, Da id Seh , G ego y Da dyk, J. B adley Chen, Robe Mu h,
Ta is O mandy, Shiki Okasaka, Neha Na ula, and Nicholas Fullaga . Na i e
clien : A sandbox o po able, un us ed x86 na i e code. In P oceedings o
IEEE Symposium on Secu i y and P i acy (Oakland), 2009.
[144]
Yajin Zhou, Xiaoguang Wang, Yue Chen, and Zhi Wang. ARMlock: Ha dwa e-
based Faul Isola ion o ARM Yajin. In P oceedings o ACM SIGSAC Con e -
ence on Compu e and Communica ions Secu i y (CCS), 2014.
137