arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.13930cs.CRcs.PL

通过 eBPF 强制执行内核态有状态安全策略

Enforcement of In-Kernel Stateful Security Policies via eBPF

  • IMT School for Advanced Studies Lucca(卢卡高等研究学院)

机构由 AI 辅助整理,请以论文原文为准。

Letterio Galletta

AI总结:

针对多步历史依赖攻击,提出 BPFence 内核内运行时验证框架,通过形式语义策略语言和类型系统编译为经证明正确的有限状态监视器及 eBPF 程序,实现有状态安全策略的低开销强制执行。

AI中文摘要:

针对多租户系统上运行的工作负载的许多攻击是多步骤且历史依赖的:一系列无害操作,其恶意性质仅在执行轨迹中显现。防御这些攻击需要具有精确语义、在内核内强制执行的有状态安全策略。目前部署的方案至少在一个方面存在不足:内核内置的系统调用过滤和经典 MAC 框架是无状态的,而当前基于 eBPF 的工具通过临时的 YAML 规则表达其策略,这些规则无法捕获事件之间的时间关系,且其语义仅由实现定义。我们提出了 BPFence,一个满足上述属性的内核内运行时验证框架。BPFence 提供了一种具有形式语义的策略语言,能够表达事件之间的时间关系。它还提供了一个类型系统,静态区分内核可以控制的事件与只能观察到的事件。每个类型良好的策略都被编译成一个有限状态监视器,该监视器被证明相对于其语义是正确的,然后编译成在内核内运行的 eBPF 程序。我们在来自真实世界攻击模式的七个案例研究以及一组微基准和宏基准上评估了 BPFence,以表明强制执行开销仍然与生产部署兼容。

英文摘要:

Many attacks against workloads running on multi-tenant systems are multi-step and history-dependent: sequences of innocuous operations whose malicious nature emerges only over an execution trace. Defending against them requires security policies that are stateful, are enforced within the kernel, and have a precise semantics. Currently deployed proposals fail on at least one count: kernel's built-in syscall filtering and classical MAC frameworks are stateless, while current eBPF-based tools express their policies through ad hoc YAML rules that cannot capture temporal relations among events, and whose semantics is defined only by the implementation. We present BPFence, an in-kernel runtime-verification framework that satisfies the properties above. BPFence provides a policy language with a formal semantics that can express temporal relations among events. It also provides a type system that statically distinguishes events the kernel can control from those it can only observe. Every well-typed policy is compiled into a finite-state monitor proved correct with respect to its semantics, and then into eBPF programs that run inside the kernel. We evaluate BPFence on seven case studies drawn from real-world attack patterns, and on a set of micro- and macro-benchmarks to show that the enforcement overhead remains compatible with production deployment.

补充信息

↑