Sangam: A Confluence of Knowledge Streams

Kite: Lightweight Critical Service Domains

Show simple item record

dc.creator Mehrab, A K M Fazla
dc.creator Nikolaev, Ruslan
dc.creator Ravindran, Binoy
dc.date 2022-10-19T16:52:52Z
dc.date 2022-10-19T16:52:52Z
dc.date 2022-03-28
dc.date 2022-10-19T15:08:38Z
dc.date.accessioned 2023-03-01T18:52:05Z
dc.date.available 2023-03-01T18:52:05Z
dc.identifier http://hdl.handle.net/10919/112206
dc.identifier https://doi.org/10.1145/3492321.3519586
dc.identifier.uri http://localhost:8080/xmlui/handle/CUHPOERS/281582
dc.description Converged multi-level secure (MLS) systems, such as Qubes OS or SecureView, heavily rely on virtualization and service virtual machines (VMs). Traditionally, driver domains – isolated VMs that run device drivers – and daemon VMs use full-blown general-purpose OSs. It seems that specialized lightweight OSs, known as unikernels, would be a better fit for those. Surprisingly, to this day, driver domains can only be built from Linux. We discuss how unikernels can be beneficial in this context – they improve security and isolation, reduce memory overheads, and simplify software configuration and deployment.We specifically propose to use unikernels that borrow device drivers from existing general-purpose OSs. We present Kite which implements network and storage unikernel-based VMs and serve two essential classes of devices. We compare our approach against Linux using a number of typical micro- and macrobenchmarks used for networking and storage. Our approach achieves performance similar to that of Linux. However, we demonstrate that the number of system calls and ROP gadgets can be greatly reduced with our approach compared to Linux. We also demonstrate that our approach has resilience to an array of CVEs (e.g., CVE-2021-35039, CVE-2016-4963, and CVE- 2013-2072), smaller image size, and improved startup time. Finally, unikernelizing is doable for the remaining (non-driver) service VMs as evidenced by our unikernelized DHCP server.
dc.description Published version
dc.format application/pdf
dc.format application/pdf
dc.language en
dc.publisher ACM
dc.rights Creative Commons Attribution 4.0 International
dc.rights http://creativecommons.org/licenses/by/4.0/
dc.rights The author(s)
dc.title Kite: Lightweight Critical Service Domains
dc.type Article - Refereed
dc.type Text


Files in this item

Files Size Format View
3492321.3519586.pdf 1.813Mb application/pdf View/Open

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse