When eBPF Meets Machine Learning: On-the-fly OS Kernel Compartmentalization

Zicheng Wang, Tiejin Chen, Qinrun Dai, Yueqi Chen, Hua Wei, Qingkai Zeng
{"title":"When eBPF Meets Machine Learning: On-the-fly OS Kernel Compartmentalization","authors":"Zicheng Wang, Tiejin Chen, Qinrun Dai, Yueqi Chen, Hua Wei, Qingkai Zeng","doi":"arxiv-2401.05641","DOIUrl":null,"url":null,"abstract":"Compartmentalization effectively prevents initial corruption from turning\ninto a successful attack. This paper presents O2C, a pioneering system designed\nto enforce OS kernel compartmentalization on the fly. It not only provides\nimmediate remediation for sudden threats but also maintains consistent system\navailability through the enforcement process. O2C is empowered by the newest advancements of the eBPF ecosystem which\nallows to instrument eBPF programs that perform enforcement actions into the\nkernel at runtime. O2C takes the lead in embedding a machine learning model\ninto eBPF programs, addressing unique challenges in on-the-fly\ncompartmentalization. Our comprehensive evaluation shows that O2C effectively\nconfines damage within the compartment. Further, we validate that decision tree\nis optimally suited for O2C owing to its advantages in processing tabular data,\nits explainable nature, and its compliance with the eBPF ecosystem. Last but\nnot least, O2C is lightweight, showing negligible overhead and excellent\nsacalability system-wide.","PeriodicalId":501333,"journal":{"name":"arXiv - CS - Operating Systems","volume":"1 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2024-01-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"arXiv - CS - Operating Systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/arxiv-2401.05641","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Compartmentalization effectively prevents initial corruption from turning into a successful attack. This paper presents O2C, a pioneering system designed to enforce OS kernel compartmentalization on the fly. It not only provides immediate remediation for sudden threats but also maintains consistent system availability through the enforcement process. O2C is empowered by the newest advancements of the eBPF ecosystem which allows to instrument eBPF programs that perform enforcement actions into the kernel at runtime. O2C takes the lead in embedding a machine learning model into eBPF programs, addressing unique challenges in on-the-fly compartmentalization. Our comprehensive evaluation shows that O2C effectively confines damage within the compartment. Further, we validate that decision tree is optimally suited for O2C owing to its advantages in processing tabular data, its explainable nature, and its compliance with the eBPF ecosystem. Last but not least, O2C is lightweight, showing negligible overhead and excellent sacalability system-wide.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
当 eBPF 遇到机器学习:实时操作系统内核分区
内核分隔可有效防止初始破坏转化为成功的攻击。本文介绍了 O2C,这是一个旨在即时执行操作系统内核分隔的开创性系统。它不仅能为突发威胁提供即时补救措施,还能在执行过程中保持系统的持续可用性。O2C 借助 eBPF 生态系统的最新进展,允许在运行时将执行强制措施的 eBPF 程序植入内核。O2C率先在eBPF程序中嵌入了机器学习模型,解决了即时分区的独特挑战。我们的综合评估结果表明,O2C 能有效地将损害限制在小区内。此外,我们还验证了决策树最适合用于 O2C,因为它在处理表格数据、可解释性以及与 eBPF 生态系统的一致性方面具有优势。最后但并非最不重要的一点是,O2C 是轻量级的,其开销可以忽略不计,并且在全系统范围内具有出色的可扩展性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Analysis of Synchronization Mechanisms in Operating Systems Skip TLB flushes for reused pages within mmap's eBPF-mm: Userspace-guided memory management in Linux with eBPF BULKHEAD: Secure, Scalable, and Efficient Kernel Compartmentalization with PKS Rethinking Programmed I/O for Fast Devices, Cheap Cores, and Coherent Interconnects
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1