发表机构
Dartmouth College(达特茅斯学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究分析网络设备中Python字节码完整性被隐式信任但未受信任链覆盖的风险,并提出理解此类设计涌现行为的框架。
AI 中文摘要
编译后的Python字节码(PYC)已成为网络交换机、路由器及其他网络基础设施设备的重要组成部分。我们的分析表明,在多种设计中,位于操作软件顶层的Python代码(如企业网络交换机的管理和控制平面)的完整性被隐式信任。同时,由于与CPython加载器、字节编译器及其他Python运行时组件的复杂交互,PYC文件的完整性并未被传统信任链模型所覆盖。我们探讨了将PYC和Python运行时纳入商业企业设备事实上的可信代码库所固有的风险,并提供了一个全面的框架,以理解这些设计中的涌现行为。
英文摘要
Compiled Python bytecode (PYC) has become an essential part of network switches, routers, and other network infrastructure devices. Our analysis shows that its integrity is implicitly trusted in multiple designs that make use of Python code at the top of the operational software, such as the management and control pane of enterprise network switches. At the same time, the integrity of PYC files is not covered under the traditional chain-of-trust models, due to complex interactions with the CPython loader, byte compiler, and other Python runtime components. We explore the risks inherent in including PYC and Python runtimes in the de facto trusted code basis of commercial enterprise equipment and offer a comprehensive framework for understanding emergent behaviors in these designs.
CommentsWork in progress. Presented at the 2026 Symposium on the Science of Security (HotSoS 2026), Session 2, April 14, 2026. Session listing: https://sos-vo.org/group/hotsos/2026/hernandez 9 pages, 2 figures, 4 tables