SearcharxivSearch

arXiv subjects

Christoph Baumann

Publications and source records attributed to Christoph Baumann.

9 recordsLinked to original sources

Friend or Foe Inside? Exploring In-Process Isolation to Maintain Memory Safety for Unsafe Rust

Rust is a popular memory-safe systems programming language. In order to interact with hardware or call into non-Rust libraries, Rust provides \emph{unsafe} language features that shift responsibility for ensuring memory safety to the developer. Failing to do so, may lead to memory safety violations in unsafe code which can violate safety of the entire application. In this work we explore in-process isolation with Memory Protection Keys as a mechanism to shield safe program sections from safety violations that may happen in unsafe sections. Our approach is easy to use and comprehensive as it prevents heap and stack-based violations. We further compare process-based and in-process isolation mechanisms and the necessary requirements for data serialization, communication, and context switching. Our results show that in-process isolation can be effective and efficient, permits for a high degree of automation, and also enables a notion of application rewinding where the safe program section may detect and safely handle violations in unsafe code.

cs.CR

End-to-End Security for Distributed Event-Driven Enclave Applications on Heterogeneous TEEs

This paper presents an approach to provide strong assurance of the secure execution of distributed event-driven applications on shared infrastructures, while relying on a small Trusted Computing Base. We build upon and extend security primitives provided by Trusted Execution Environments (TEEs) to guarantee authenticity and integrity properties of applications, and to secure control of input and output devices. More specifically, we guarantee that if an output is produced by the application, it was allowed to be produced by the application's source code based on an authentic trace of inputs. We present an integrated open-source framework to develop, deploy, and use such applications across heterogeneous TEEs. Beyond authenticity and integrity, our framework optionally provides confidentiality and a notion of availability, and facilitates software development at a high level of abstraction over the platform-specific TEE layer. We support event-driven programming to develop distributed enclave applications in Rust and C for heterogeneous TEE, including Intel SGX, ARM TrustZone and Sancus. In this article we discuss the workings of our approach, the extensions we made to the Sancus processor, and the integration of our development model with commercial TEEs. Our evaluation of security and performance aspects show that TEEs, together with our programming model, form a basis for powerful security architectures for dependable systems in domains such as Industrial Control Systems and the Internet of Things, illustrating our framework's unique suitability for a broad range of use cases which combine cloud processing, mobile and edge devices, and lightweight sensing and actuation.

cs.CR

Exploring the Environmental Benefits of In-Process Isolation for Software Resilience

Memory-related errors remain an important cause of software vulnerabilities. While mitigation techniques such as using memory-safe languages are promising solutions, these do not address software resilience and availability. In this paper, we propose a solution to build resilience against memory attacks into software, which contributes to environmental sustainability and security.

cs.CR

Unlimited Lives: Secure In-Process Rollback with Isolated Domains

The use of unsafe programming languages still remains one of the major root causes of software vulnerabilities. Although well-known defenses that detect and mitigate memory-safety related issues exist, they don't address the challenge of software resilience, i.e., whether a system under attack can continue to carry out its function when subjected to malicious input. We propose secure rollback of isolated domains as an efficient and secure method of improving the resilience of software targeted by run-time attacks. We show the practicability of our methodology by realizing a software library for Secure Domain Rollback (SDRoB) and demonstrate how SDRoB can be applied to real-world software.

cs.CR

Quantifying and mapping covalent bond scission during elastomer fracture

Many new soft but tough rubbery materials have been recently discovered and new applications such as flexible prosthetics, stretchable electrodes or soft robotics continuously emerge. Yet, a credible multi-scale quantitative picture of damage and fracture of these materials has still not emerged, due to our fundamental inability to disentangle the irreversible scission of chemical bonds along the fracture path from dissipation by internal molecular friction. Here, by coupling new fluorogenic mechanochemistry with quantitative confocal microscopy mapping, we uncover how many and where covalent bonds are broken as an elastomer fractures. Our measurements reveal that bond scission near the crack plane can be delocalized over up to hundreds of micrometers and increase by a factor of 100 depending on temperature and stretch rate, pointing to an intricated coupling between strain rate dependent viscous dissipation and strain dependent irreversible network scission. These findings paint an entirely novel picture of fracture in soft materials, where energy dissipated by covalent bond scission accounts for a much larger fraction of the total fracture energy than previously believed. Our results pioneer the sensitive, quantitative and spatially-resolved detection of bond scission to assess material damage in a variety of soft materials and their applications.

cond-mat.soft

Lessons Learned From Microkernel Verification -- Specification is the New Bottleneck

Software verification tools have become a lot more powerful in recent years. Even verification of large, complex systems is feasible, as demonstrated in the L4.verified and Verisoft XT projects. Still, functional verification of large software systems is rare - for reasons beyond the large scale of verification effort needed due to the size alone. In this paper we report on lessons learned for verification of large software systems based on the experience gained in microkernel verification in the Verisoft XT project. We discuss a number of issues that impede widespread introduction of formal verification in the software life-cycle process.

cs.SE

Measurements of the electron-positron continuum in ALICE

The status of the analysis of electron-positron pairs measured by ALICE in pp collisions at $\sqrt{s} = 7$ TeV and central Pb-Pb collisions at $\sqrt{s_\mathrm{NN}}=2.76$ TeV is presented. Key questions and the main challenges of the analysis are discussed on the basis of first raw invariant mass spectra for both collision systems.

nucl-ex

PHENIX results on the $\sqrt{s_\mathrm{NN}}$ dependence of jet quenching

The PHENIX experiment has established jet quenching at a center-of-mass energy of 200 GeV in Au+Au collisions. Recent measurements of Cu+Cu collisions at the same center-of-mass energy support a parton energy loss scenario. Furthermore, the onset of jet quenching was studied in Cu+Cu collisions for three center-of-mass energies 22.4, 62.4 and 200 GeV.

nucl-ex

Search for direct photons in p+Pb and p+C collisions at sqrt(sNN) = 17.4 GeV

Upper limits on direct photon production were determined as a function of the transverse momentum for 0.7 < pT <= 3.2 GeV/c with the WA98 experiment in p+C and p+Pb collisions at sqrt(sNN) = 17.4 GeV. The results are compared to direct photon measurements in Pb+Pb collisions at sqrt(sNN) = 17.3 GeV by WA98. Implications for a possible thermal direct photon contribution are discussed.

nucl-ex