Software fault isolation with API integrity and multi-principal modules
to partition the privileges held by a single shared module into multi- ple principals ... enforces API integrity at runtime through software fault isolation techniques.
[ lxfi:sosp11.pdf - Read/Download File
LXFI, a software fault isolation system - The University of Texas at
Apr 4, 2012 ... LXFI, a software fault isolation system ... many exploits attack kernel modules: 67 % of Linux ... example about enforce argument integrity ... Mao etc, SOSP'11, Software fault isolation with API integrity and multi-principal modules.
[ lec19.pdf - Read/Download File
Diagnosys: Automatic Generation of a Debugging Interface to - Hal
Sep 12, 2012 ... of a kernel internal API function that returns NULL as the ...... Software fault isolation with API integrity and multi-principal modules. In SOSP'11.
[ diagnosys-ase12.pdf - Read/Download File
Codejail: Application-transparent Isolation of Libraries with Tight
solutions for software component isolation assume simple interactions ...... Software fault isolation with api integrity and multi-principal modules. In Proc. of ACM.
[ esorics12.pdf - Read/Download File
Behave or Be Watched: Debugging with Behavioral Watchpoints
Nov 3, 2013 ... We introduce behavioral watchpoints, a new software-based ..... Software fault isolation with API integrity and multi-principal modules. In SOSP ...
[ debugging-with-behavioral-watchpoints.pdf - Read/Download File
Defeating Kernel Driver Purifier - University of Delaware
malicious kernel API calls from being removed by kernel driver purifiers, this new type ...... Software fault isolation with api integrity and multi-principal modules.
[ purifier.pdf - Read/Download File
Tailored Application-specific System Call Tables
system calls used, and a runtime enforcement module that ...... Fast Byte- granularity Software Fault Isolation. In ... API integrity and multi-principal modules .
[ syscall.pdf - Read/Download File
Quantifiable Run-time Kernel Attack Surface Reduction
can attempt to isolate kernel modules of commodity OSes directly, especially device drivers [3 ......  Mao, Y., Chen, H., Zhou, D., Wang, X., Zeldovich, N., Kaashoek, M.F.: Software fault isolation with api integrity and multi-principal modules.
[ kurmus-dimva14.pdf - Read/Download File
Understanding Modern Device Drivers - Computer Sciences User
Mar 7, 2012 ... isolation. We also find that drivers for different buses and classes ...... Software fault isolation with api integrity and multi-principal modules.
[ asplos12_drivers.pdf - Read/Download File
Guarded Modules: Adaptively Extending the VMM's - V3VEE
Jun 20, 2014 ... We present a software technique, guarded ex- ecution of privileged code .... for commodity driver reuse and fault isolation  shows promise, but these ...... Software fault isolation with api integrity and multi-principal modules.
[ icac14.pdf - Read/Download File
Solutions to Mobile Agent Security Issues in Open Multi - IRJET
free hopping of mobile agents in open multi-agent systems ..... Software fault isolation with API integrity and multi-principal modules. in Proceedings of the.
[ IRJET-V2I5104.pdf - Read/Download File
Between Mutual Trust and Mutual Distrust: Practical Fine - Usenix
Jul 10, 2015 ... In other words, could different principal threads have dif- .... 2) Software fault isolation. Address space ... ware fault isolation [30, 17] did an innovative work on ... modules and kernel data. ... integrity and does not check memory reads due to per- ... vide a label-based security model and a set of APIs for.
[ atc15-paper-wang-jun.pdf - Read/Download File
a research platform deconflating hardware virtualization and protection
Mar 3, 2012 ... eralised platform for research into the hardware-software interface and its specific ... success derives from the principle of least privilege . Experi- ...... Software fault isolation with API integrity and multi- principal modules.
[ 2012resolve-cheri.pdf - Read/Download File
The CHERI capability model: Revisiting RISC in an age of risk
enforcement and fault isolation in hardware rather than soft- ware, and that the CHERI ...... broken into components to in- dicate area cost by module. ..... “ Software fault isolation with API integrity and multi-principal mod- ules,” in SOSP 2011: ...
[ 201406-isca2014-cheri.pdf - Read/Download File
Using Shadow Page Cache to Improve Isolated Drivers Performance
Feb 11, 2015 ... rithm: according to the principle of locality, this algorithm caches the ... effectively isolate drivers' write operation faults; (2) complete transparency ... module file. Isolation ...... F. Kaashoek, “Software fault isolation with API integrity and multi- principal modules,” in Proceedings of the 23rd ACM. Symposium on ...
[ 896519.pdf - Read/Download File
Protecting Browsers from Extension Vulnerabilities
tion, and strong isolation. ... multi-layer vulnerability is more difficult than exploiting a ... A browser extension is a third-party software module ... mitigate XSS attacks, Firefox provides a sandbox API, ..... write ρ ↩→η α when principal ρ has a reference to an in- ..... lem of running native plug-in code securely using fault iso-.
[ 04.pdf - Read/Download File
contract from widely used configurable contract modules. Once the ..... Software Fault Isolation (SFI) relies on compiling software to a reduced instruction set, or.
[ Codius Whitepaper.pdf - Read/Download File
Virtual Ghost: Protecting Applications from Hostile Operating Systems
software fault isolation; control-flow integrity; malicious op- .... Virtual Ghost by adding a malicious module to the FreeBSD kernel, replacing ..... SVA-OS API calls.
[ VirtualGhost-ASPLOS-2014.pdf - Read/Download File
Tiered Fault Tolerance for Long-Term Integrity - OceanStore
trusted fault tier, which must never fail, or an untrusted fault ... if all involved hardware and software components are op- ... However, this multi-tier approach enables us to struc- ... facility for a moded, attested storage module (MAS), ..... is digitally signed by principal i. ..... (i.e., “booted”) in isolation of any currently running S.
[ bonafide.pdf - Read/Download File
Shreds: Fine-grained Execution Units with Private Memory - Long Lu
toolchain and the OS module that together enable shreds on. Linux. ... multiple shreds. Shreds ... call a private API can run in a shred whose s-pool contains the API code .... Software fault isolation (SFI)  and sim- .... In principle, a shred should contain a minimum .... form control-flow integrity (CFI) to ensure that in- process.
[ shreds_oakland16.pdf - Read/Download File