JOURNAL ARTICLE

Interrupt Stack Protection for Linux Kernel in Hardware Virtualization Layer of ARM64 Architecture.

  • Published In: Journal of Circuits, Systems & Computers, 2023, v. 32, n. 16. P. 1 1 of 3

  • Database: Academic Search Ultimate 2 of 3

  • Authored By: Xiong, Chenglai; Yu, Xuejun; Yang, Jialing; Xie, Guoqi 3 of 3

Abstract

Kernel security is of paramount importance in computer systems. As the number of vulnerabilities in the kernel continues to grow, computer systems security risks are increasing. To prevent the kernel interrupt stack from being attacked, researchers provide discussion over complete hypervisor supervision and kernel co-layer security domain techniques. Complete hypervisor supervision brings a heavy overhead and co-layer security domain techniques cannot achieve privilege-level isolation. We focus on memory-based security threats in kernel security vulnerabilities, protecting the kernel at a higher level by using virtualization technology. Compared with the existing work, our implementation method achieves a small performance loss to protect the interrupt stack. We have implemented our system on openEuler operating systems and Phytium processors. Although the deployment of protection code will result in increased kernel interrupt latency and processor overhead, experimental verification shows that the overall system overhead is acceptable. [ABSTRACT FROM AUTHOR]

Additional Information

  • Source:Journal of Circuits, Systems & Computers. 2023/11, Vol. 32, Issue 16, p1
  • Document Type:Article
  • Subject Area:Computer Science
  • Publication Date:2023
  • ISSN:0218-1266
  • DOI:10.1142/S0218126623502705
  • Accession Number:173887818
  • Copyright Statement:Copyright of Journal of Circuits, Systems & Computers is the property of World Scientific Publishing Company and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)

Looking to go deeper into this topic? Look for more articles on EBSCOhost.