DocumentCode
3452668
Title
Vulnerabilities in synchronous IPC designs
Author
Shapiro, Jonathan S.
Author_Institution
Dept. of Comput. Sci., Johns Hopkins Univ., MD, USA
fYear
2003
fDate
11-14 May 2003
Firstpage
251
Lastpage
262
Abstract
Recent advances in interprocess communication (IPC) performance have been exclusively based on thread-migrating IPC designs. Thread-migrating designs assume that IPC interactions are synchronous, and that user-level execution will usually resume with the invoked process (modulo preemption). This IPC design approach offers shorter instruction path lengths, requires fewer locks, has smaller instruction and data cache footprints, dramatically reduces TLB overheads, and consequently offers higher performance and lower timing variance than previous IPC designs. With care, it can be performed as an atomic unit of operation. While the performance of thread-migrating IPC has been examined in detail, the vulnerabilities implicit in synchronous IPC designs have not been examined in depth in the archival literature, and their implications for IPC design have been actively misunderstood in at least one recent publication. In addition to performance, a sound IPC design must address concerns of asymmetric trust and reproducibility and provide support for dynamic payload lengths. Previous IPC designs, including those of EROS, Mach, L4, Flask, and Pebble, satisfy only two of these three requirements. In this paper, we show how these three design objectives can be met simultaneously. We identify the conflict of requirements and illustrate how their collision arises in two well-documented IPC architectures: L4 and EROS. We then show how all three design objectives are simultaneously met in the next generation EROS IPC system.
Keywords
multi-threading; operating system kernels; performance evaluation; security of data; EROS; L4; asymmetric trust; capability systems; dynamic payload lengths; interprocess communication; operating systems; performance; reproducibility; synchronous IPC designs; thread-migrating designs; vulnerabilities; Communication system security; Computer science; Operating systems; Payloads; Performance analysis; Protection; Reproducibility of results; Resumes; Testing; Timing;
fLanguage
English
Publisher
ieee
Conference_Titel
Security and Privacy, 2003. Proceedings. 2003 Symposium on
ISSN
1081-6011
Print_ISBN
0-7695-1940-7
Type
conf
DOI
10.1109/SECPRI.2003.1199341
Filename
1199341
Link To Document