高级检索

硬件辅助的进程内安全防护技术

Hardware-Assisted Intra-Process Protection Technologies

  • 摘要: 随着软件生态高度模块化和第三方代码的广泛集成,传统“进程内一切平等”的资源访问模型暴露出安全隐患。单纯依靠软件安全防护机制面临性能瓶颈、元数据易被篡改及兼容性差等固有局限,因此处理器硬件辅助的进程内安全防护机制成为一个重要的发展方向。文章综述了处理器硬件辅助的进程内安全防护技术。首先梳理了商业处理器中的现有硬件机制,包括NX位、CET、MPK、PAC和MTE等,指出其中的共性问题,如缺少可信基、标签空间受限、系统调用与I/0保护缺失等。随后,从指针级检查、隔离域保护、系统调用检查以及寄存器和指令集的分区保护4个方向系统地分析了学术界的最新研究进展和发展趋势,并总结了这一领域仍然面临的技术挑战。

     

    Abstract: As software ecosystems become highly modular and third-party codes are widely integrated, the traditional "all-equal" resource access model within a process has exposed security vulnerabilities. Relying solely on software-based security mechanisms faces inherent limitations, including performance bottlenecks, susceptibility to metadata tampering, and poor compatibility. Consequently, hardware-assisted security protection has emerged as an important development direction. This paper presents a survey of processor hardware-assisted intra-process protection technologies. It begins by examining existing mechanisms in commercial processors—namely, NX bit, CET, MPK, PAC, and MTE—and identifies common deficiencies, including the absence of an in-process trusted computing base, insufficient tag space, a lack of system call protection as well as a lack of register and instruction set partition. Subsequently, it systematically analyzes the latest academic advances and emerging trends across four research directions: pointer-level checking, compartment-based isolation, system call interception, and register partitioning, while also highlighting the limitations of current solutions. Finally, it outlines the remaining technical challenges that persist in this field.

     

/

返回文章
返回