arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.17525cs.CR

你不得进入 Ring-0!一种面向个人电脑的用户隐私友好型反作弊架构

You Shall Not Pass into Ring-0! A User Privacy-Friendly Anti-Cheat Architecture for Personal Computers

Santosh Gokul Narayanan, Giovanni Paladino, Chuqi Zhang, Sangho Lee, Zhenkai Liang, Adil Ahmad

首次发表
浏览论文内容

中文总结 AI 辅助

针对内核级反作弊的隐私问题,提出Tirith架构,通过受保护虚拟机运行游戏并利用可信虚拟化监视器监控,无需内核级组件,兼顾检测与性能。

中文摘要 AI 辅助

内核级反作弊机制在竞技视频游戏中能有效对抗恶意玩家行为,但因其在特权模式(即 x86 中的 ring-0)下安装不可验证组件而引发严重的用户隐私担忧。现有研究主要聚焦于提升反作弊的有效性,用户隐私问题却在很大程度上被忽视。Tirith 是一种反作弊架构,通过两个关键思想解决此问题。首先,Tirith 不在玩家(作为 root 管理员)可控的常规进程中运行视频游戏,而是在受保护的虚拟机中执行游戏,这些虚拟机天然地将计算与不受信任的管理员隔离。其次,为监控沙箱之外的用户行为(例如,检测用户是否运行恶意驱动程序),Tirith 利用一个同时受玩家和开发者信任的虚拟化监视器。这些思想共同消除了运行不受信任的内核级反作弊机制的需求,同时针对多种常见作弊机制提供了与这类解决方案同等水平的保护。然而,实现这些思想面临的主要挑战是,现有的虚拟机软件栈并非为运行视频游戏而设计,会产生显著的安全和性能问题。我们通过提出一个面向游戏的安全导向型库操作系统内核,以及一个用于接近原生渲染和显示性能的高效图形共享流水线来解决这些问题。总之,在不损害作弊行为检测或性能的前提下,这项工作将用户隐私提升为个人电脑中的一等公民。

英文摘要

Kernel-level anti-cheats are effective against malicious player behavior in competitive video games, but raise significant user privacy concerns regarding installing unverifiable components at privileged modes (i.e., ring-0 in x86). While existing research has focused on improving the effectiveness of anti-cheats, the user privacy concern has been largely ignored. Tirith is an anti-cheat architecture that addresses this problem using two key ideas. First, instead of running video games within regular processes that players (as root admins) have control over, Tirith executes video games in Protected Virtual Machines that naturally sandbox computations from untrusted admins. Second, to monitor user behavior outside the sandbox (e.g., see if they are running malicious drivers), Tirith leverages a virtualization monitor that is trusted by both players and developers. Together, these ideas remove the need to run untrusted kernel-level anti-cheats, while providing the same level of protection compared to such solutions against a wide-range of common cheating mechanisms. The main challenge we face in implementing these ideas, however, is that the existing software stack for virtual machines is not designed to run video games and creates significant security and performance problems. We address these problems by proposing a security-focused Library OS kernel for games and an efficient graphics sharing pipeline for near-native rendering and display performance. In summary, without compromising on cheating behavior detection or performance, this work makes user privacy a first-class citizen in personal computers.

发表机构

  • Nokia of America Corporation(诺基亚美国公司)
  • New York University(纽约大学)
  • National University of Singapore(新加坡国立大学)
  • Microsoft Research(微软研究院)
  • Arizona State University(亚利桑那州立大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑