arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

你的数据库系统在生产环境中应使用硬件辅助的内存安全扩展吗?

Should Your Database Systems Use Hardware-Assisted Memory Safety Extensions in Production?

Ilya Meignan--Masson, Martin Fink, Masanori Misono, Dimitrios Stavrakakis, Pramod Bhatotia

arXiv 2610.11525首次发表:更新:

发表机构

Technical University of Munich(慕尼黑工业大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文通过数据库三难困境评估硬件辅助内存安全扩展MTE和CHERI,发现MTE开销约10%、可移植性高,CHERI安全更优但开销20-60%、移植量大,为数据库架构师提供实用指南。

AI 中文摘要

数据库系统为满足性能要求,主要用不安全语言(如C/C++)开发,依赖底层内存管理,但这种依赖使其易出现系统性内存安全问题,损害可靠性、一致性、安全性和持久性。通过对主流数据库系统的广泛漏洞分析,我们发现尽管数据库测试工具不断进步,这些内存安全问题仍存在于生产环境中。新兴的硬件辅助扩展(如Arm的内存标记扩展MTE和CHERI)为缓解内存安全问题提供了有前景的路径,但其在数据库系统的特殊约束下的实际适用性和性能开销仍未被充分探索。本文从我们定义的数据库三难困境(安全、性能、可移植性之间的基本权衡)视角评估硬件扩展,以确定其对生产级数据库系统的可行性。我们首次在数据库工作负载套件中对MTE和CHERI进行了并排比较。我们的自底向上研究涵盖微架构、编译器/运行时/操作系统栈、核心数据结构(ART、B+树、哈希表、跳表、链表和队列)以及完整数据库系统(Redis、LevelDB、SQLite、MySQL、DuckDB和LadyBugDB),以表征它们的性能、安全保障和采用的难易程度。我们发现,虽然硬件扩展可提供近确定性的保护,但它们会引入非均匀的性能开销:MTE具有高可移植性,开销适中(约10%);CHERI提供更优的安全保障,但性能惩罚更高(20-60%),且移植工作量大。我们的研究为数据库系统架构师提供了实用指南,助力其利用硬件辅助安全机制构建下一代可靠、安全的数据库。

英文摘要

Database systems are predominantly developed in unsafe languages (e.g., C/C++) to meet performance requirements through low-level memory management, yet this reliance renders them prone to systemic memory-safety issues that compromise reliability, consistency, security, and durability. Through an extensive bug analysis of prominent database systems, we show that these memory-safety issues persist in production environments despite advancements in database testing tools. While emerging hardware-assisted extensions, such as Arm's Memory Tagging Extension (MTE) and CHERI, offer a promising mitigation path for memory safety, their practical applicability and performance overhead within the specialized constraints of database systems remain largely unexplored. In this paper, we evaluate hardware extensions through the lens of what we define as the database trilemma: the fundamental trade-off between safety, performance, and portability, to determine their viability for production-grade database systems. We provide the first side-by-side comparison of MTE and CHERI across a database workload suite. Our bottom-up study spans microarchitecture, the compiler/runtime/OS stack, core data structures (ART, B+Tree, hash table, skip list, linked list, and queue), and full database systems (Redis, LevelDB, SQLite, MySQL, DuckDB, and LadyBugDB) to characterize their performance, safety guarantees, and ease of adoption. We find that while hardware extensions can offer near-deterministic protection, they introduce non-uniform performance taxes: MTE provides high portability with modest overheads (~10%), while CHERI delivers superior safety guarantees with higher performance penalties (20-60%) and significant porting effort. Our study equips database systems architects with an actionable guide toward building the next generation of reliable, secure databases using hardware-assisted safety mechanisms.

DOI:10.1145/3856373

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑