This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

+47 -48
View File
@@ -4,18 +4,18 @@ The reference monitor is an abstract concept
> An access control concept that refers to an abstract machine that mediates all access to objects by subjects
- Must be tamper proof
- Must be tamper-proof
- Must *always be invoked* when access to an object is required
- Must be small enough to be verifiable / subject to analysis to ensure correctness
##### Placement
- Can be placed anywhere within the system
- Hardware - dedicated registers for defining privileges
- Operating system kernel - virtual machine hyper-visor
- Operating system - Windows security reference monitor
- Services layer - `JVM`, `.NET`
- Application layer - Firewalls
- Hardware - dedicated registers for defining privileges
- Operating system kernel - virtual machine hypervisor
- Operating system - Windows security reference monitor
- Services layer - `JVM`, `.NET`
- Application layer - Firewalls
Reference monitors could be placed in a variety of locations relative to the program being run
@@ -26,27 +26,27 @@ The last example where the program contains its own reference monitor, as found
###### Lower is better
- Using a reference monitor or other security features at a lower level means:
- We can **assure** a higher degree of security
- Usually **simple structures** to implement
- Reduced performance **overheads**
- Has to be extremely quick as many calls will be made
- Fewer layer below attack possibilities
- We can **assure** a higher degree of security
- Usually **simple structures** to implement
- Reduced performance **overheads**
- Has to be extremely quick as many calls will be made
- Fewer layer below attack possibilities
- However
- Access control decisions are far removed from applications
- Access control decisions are far removed from applications
#### OS Integrity
- The operating system
- Arbitrates access requests
- Is itself a resource that must be accessed
- Arbitrates access requests
- Is itself a resource that must be accessed
- This is a conflict, we want to use the OS but not mess with it
> Users must not be able to modify the operating system
- Modes of operation
- Defines which actions are permitted in which mode e.g. system calls, machine instructions, I/O
- Defines which actions are permitted in which mode e.g. system calls, machine instructions, I/O
- Controlled Invocation
- Allows us to execute privileged instructions safely, before returning to user code
- Allows us to execute privileged instructions safely, before returning to user code
We must distinguish computations done on behalf of:
@@ -61,10 +61,10 @@ In practice, Windows and Unix only use Ring 0&3 to save on overhead
### Controlled Invocation
- Many functions are helf at kernel level, but are quite reasonably called from within user level code
- Network and File IO
- Memory allocation
- Halting the CPU (at shutdown only)
- Many functions are held at kernel level, but are quite reasonably called from within user-level code
- Network and File IO
- Memory allocation
- Halting the CPU (at shutdown only)
- We need a mechanism to transfer safely between kernel mode (ring 0) and user mode (ring 3)
> We don’t actually perform privileged operations, we asking the operating system to perform them for us - The operating system can refuse to do it
@@ -72,7 +72,7 @@ In practice, Windows and Unix only use Ring 0&3 to save on overhead
##### Interrupts
- Exceptions or Interrupts
- In many ways is the hardware equivalent to a software exception - not always bad
- In many ways is the hardware equivalent to a software exception - not always bad
- Handled by an interrupt handler which resolves the issue and returns to the original code
Processing an Interrupt
@@ -85,9 +85,9 @@ Processing an Interrupt
- Descriptors hold information on crucial system objects like kernel structure locations
- Descriptors are held in descriptor tables
- Contain a Descriptor Privilege Level (DPL)
- Contain a Descriptor Privilege Level (DPL)
- Descriptors are indexed by selectors
- Loaded when required (jump calls)
- Loaded when required (jump calls)
- The CPU protects the kernel by checking the Current Privilege Level (CPL) when a Selector is loaded
##### Interrupt Gates
@@ -101,11 +101,11 @@ Processing an Interrupt
###### Modern Kernels
- Intel introduced the `sysenter` and `sysexit` operations with the Pentium II
- performs with much less overhead
- performs with much less overhead
![1645472755.png](img/1645472755.png)
We got immediately in to ring 0
We go immediately into ring 0
However where we go next is dictated by the `sysenter` pointer, users cannot write to `sysenter`
@@ -119,20 +119,20 @@ However where we go next is dictated by the `sysenter` pointer, users cannot wri
- A process is a program being executed currently
- Important unit of control
- Exists in its own address space
- Communicates with other processes via the OS
- Separation for security
- Exists in its own address space
- Communicates with other processes via the OS
- Separation for security
- A thread is a strand of execution within a process
- Share a common address space
- Share a common address space
- Segmentation - divides data into logical units
- Good for security
- Challenging memory management
- Not used much in modern OSs
- Modern OSs only have two segments, one for user space, the other for kernel space
- Good for security
- Challenging memory management
- Not used much in modern OSs
- Modern OSs only have two segments, one for user space, the other for kernel space
- Paging - divides memory into pages of equal size
- Efficient memory management
- Less good for access control
- Extremely common in modern OSs
- Efficient memory management
- Less good for access control
- Extremely common in modern OSs
##### Page Tables
@@ -144,17 +144,17 @@ However where we go next is dictated by the `sysenter` pointer, users cannot wri
###### Meltdown
- In most operating systems, the entire kernel is stored in the upper address space
- Pages in this area are flagged as supervisor, and cannot be access outside ring 0
- Pages in this area are flagged as supervisor, and cannot be accessed outside ring 0
- Meltdown is an exploit that allows us to read this privileged memory
- We do this using a *side-channel*
- We do this using a *side-channel*
![1645474135.png](img/1645474135.png)
- In Intel CPUs, it’s common to speculatively evaluate code prior reaching it
- E.g. conditionals
- **Significant** speed up
- No harm done, changes are just rolled back
- But the **cache isn’t rolled back**
- In Intel CPUs, it’s common to speculatively evaluate code prior to reaching it
- E.g. conditionals
- **Significant** speed-up
- No harm done, changes are just rolled back
- But the **cache isn’t rolled back**
- This is called side-channelling and cache timing
```java
@@ -179,8 +179,7 @@ x = memory[data * 4096];
4. Page 117 was quicker
- Meltdown attempts to read a value from kernel memory
- Read from kernel
- Mask out single bit
- Access user memory at that location
- If we repeat we can read all memory in kernel space
- Read from kernel
- Mask out single bit
- Access user memory at that location
- If we repeat we can read all memory in kernel space