CHORS: hardening high-assurance security systems with trusted computing


연구 분야: Verification



학회: SAC '22: Proceedings of the 37th ACM/SIGAPP Symposium on Applied Computing


초록

High-assurance security systems require strong isolation from the untrusted world to protect the security-sensitive or privacy-sensitive data they process. Existing regulations impose that such systems must execute in a trustworthy operating system (OS) to ensure they are not collocated with untrusted software that might negatively impact their availability or security. However, the existing techniques to attest to the OS integrity fall short due to the cuckoo attack. We present and formally prove a novel defense against this attack. We implement it as part of an integrity monitoring and enforcement system that attests to the remote OS integrity 3.7× -- 8.5× faster than the existing integrity monitoring systems. We demonstrate its practicality by protecting a real-world eHealth application, and performing micro and macro-benchmarks.


Author Profile
Wojciech Ozga

TU Dresden Germany

Germany
Author Profile
Rasha Faqeh

TU Dresden Germany

Germany
Author Profile
Do Le Quoc

Huawei Research

정보 없음

📄 논문 정보

발행 연도 2022년
인용수 3
출판 국가 Germany
사이트 ACM
좋아요 수 0

연관 논문 목록 (199건)