arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

构建“楚门的世界”:一种基于TrustZone的轻量级带外内核安全监控框架

Building the Truman Show: A TrustZone-Based Framework for Lightweight Out-of-band Kernel Security Monitoring

Zhenling Duan, Pan Dong, Renshuang Jiang, Xiaoxiang Fang, Bao Li

arXiv 2608.29758首次发表:更新:

发表机构

College of Computer Science and Technology, National University of Defense Technology(国防科技大学计算机学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对传统内核防护易被绕过的问题,提出基于ARM TrustZone的轻量级带外监控框架LOOM,通过硬件隔离、语义重构等机制实现低开销的内核攻击检测与缓解,已在飞腾D2000平台验证有效。

AI 中文摘要

操作系统中漏洞数量不断增加,加上复杂的内核级威胁(如rootkit),削弱了传统内核内保护机制的有效性。由于这些防御机制与内核处于同一特权级别,它们共享相同的攻击面,一旦内核被攻破就可能被绕过。基于隔离的安全方法通过将安全逻辑与内核分离提供更强的保护,但严格的隔离常引入语义鸿沟,限制系统可见性并阻碍及时的威胁检测。本文提出LOOM,一种基于ARM TrustZone构建的轻量级带外操作系统监控架构。通过利用TrustZone的硬件强制隔离,LOOM建立了独立于内核的防篡改监控环境。为弥合语义鸿沟,我们在安全世界中设计了轻量级语义重构机制,选择性捕获进程控制块、内核模块等关键内核对象的状态和行为模式。此外,LOOM引入双阶段危害预防机制,结合原子内存保护与中断驱动的自适应代理,检测并缓解内核rootkit活动。还加入地址转换缓存以优化重复地址访问、降低监控开销。总体而言,我们开发了包含平台层、功能层和辅助层的多层协作架构,用于安全高效的内核监控。已在Phytium D2000平台上实现LOOM原型,实验结果表明,LOOM产生的开销可忽略不计,同时保持强大的监控能力。此外,基于CVE案例的安全能力分析显示,LOOM可检测并缓解多种内核攻击。

英文摘要

The increasing number of vulnerabilities in operating systems, together with sophisticated kernel-level threats (e.g., rootkits), has weakened the effectiveness of traditional in-kernel protection mechanisms. Since these defenses operate at the same privilege level as the kernel, they share the same attack surface and can be bypassed once the kernel is compromised. Isolation-based security approaches provide stronger protection by separating security logic from the kernel, but strict isolation often introduces semantic gaps that limit system visibility and hinder timely threat detection. In this paper, we present LOOM, a lightweight out-of-band operating system monitoring architecture built on ARM TrustZone. By leveraging TrustZone's hardware-enforced isolation, LOOM establishes a tamper-resistant monitoring environment independent of the kernel. To bridge the semantic gap, we design a lightweight semantic reconstruction mechanism in the Secure World. It selectively captures the states and behavioral patterns of critical kernel objects, such as process control blocks and kernel modules. Additionally, LOOM introduces a dual-stage hazard prevention mechanism that combines atomic memory protection with an interrupt-driven adaptive agent to detect and mitigate kernel rootkit activities. An address translation cache is further incorporated to optimize repeated address access and reduce monitoring overhead. Overall, we develop a multi-layered collaborative architecture with platform, functional, and auxiliary layers for secure and efficient kernel monitoring. A prototype of LOOM has been implemented on the Phytium D2000 platform. Experimental results indicate that LOOM incurs negligible overhead while maintaining a strong monitoring capability. Furthermore, a security capability analysis based on CVE cases demonstrates that LOOM can detect and mitigate various kernel attacks.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑