img-logo-etablissements-partenaires-SoSySec-2023
cadre-bandeau-WOS23-28-11-2023
img-Pierre-Olivier-SoSySec-8-12-2023

Software Compartmentalization
and the Challenge of Interfaces

Pierre Olivier, Lecturer in Computer Architecture
at University of Manchester

(Cliquer sur l'image pour lancer la vidéo)

SoSySec seminar- 2023, december 8

https://seminaires-dga.inria.fr/

The slides (Pdf)

Memory Safety 00:00:00:00

Software Compartmentalization 00:06:46:13

Interface Security 00:30:27:15

The Path Forward 00:51:49:19

Links & credits 00:57:08:00

img-hautPage

 

Abstract:

In this talk, I first gived an overview of software compartmentalization and present its general principles, as well as the challenges that researchers in this field still face today.

I focused in particular on the issue of securing inter-compartment boundaries, which has been overlooked by many recent compartmentalization studies.

In that context, I presented ConfFuzz [1, 2], a tool built by my team to measure the effect of neglecting securing compartment interfaces.
Our results show that failure to put proper interface security in place leads to the loss of most security guarantees in many compartmentalized schenarios.

[1] Lefeuvre, Hugo, Vlad-Andrei Bădoiu, Yi Chien, Felipe Huici, Nathan Dautenhahn, and Pierre Olivier. "Assessing the Impact of Interface Vulnerabilities in Compartmentalized Software." In Proceedings of 30th Network and Distributed System Security (NDSS'23). Internet Society, 2022.

[2] https://conffuzz.github.io/

img-hautPage

 

1 Simg-hautPage

© 2023 Centre Inria de l'Université de Rennes