,Iso-UniK: lightweight multi-process unikernel through memory protection keys

来源 :网络空间安全科学与技术(英文版) | 被引量 : 0次 | 上传用户:huishou2088
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Unikel,specializing a minimalistic libOS with an application,is an attractive design for cloud computing.However,the Achilles’ heel of unikel is the lack of multi-process support,which makes it less flexible and applicable.Many applications rely on the process abstraction to isolate different components.For example,Apache with the multi-processing module isolates a request handler in a process to guarantee security.Prior art tackles the problem by simulating multi-process with multiple unikels,which is incompatible with existing cloud providers and also introduces high overhead.This paper proposes Iso-UniK,a new unikel design enabling multi-task applications with the support of both functionality and isolation.Iso-UniK leverages a recent hardware feature,named Intel Memory Protection Key (Intel MPK),to provide lightweight and efficient isolation for multi-process in unikel.Our design has three benefits compared with previous approaches.First,Iso-UniK does not need hypervisor support and is thus compatible with existing cloud computing platforms;second,Iso-UniK promises fast system calls with only 45 cycles;last,a process can be isolated with a flexible configuration.We have implemented a prototype based on OSv,a unikel system supporting unmodified applications.Iso-UniK can achieve fast fork operation with only 66μs for multi-process applications.Our evaluation shows that the isolation and multi-process support in Iso-UniK will not damage the applications’ performance.
其他文献
Forest disasters mainly refer to insect pest, rodent damage, forest fire and frost damage. Snow damage, windstorm, drought, flooding, landslide, mud-rock flow,
信用风险一直是商业银行所面临的最基础最主要的风险,其范围涉及贷款发放、债券投资、表外业务等领域,而发放贷款一直是银行最主要的业务活动,因此,信贷风险成为信用风险中最
“三农”问题是我国经济和社会发展中的一大难题,其中又以农民增收最难解决。目前看来,调整农业结构,推行规模经营,降低成本,发展高效农业不失为提高农业效益的一种有效途径。同时
Data security and privacy issues are magnified by the volume,the variety,and the velocity of Big Data and by the lack,up to now,of a reference data model and re
新年一过,一线城市房地产市场仿佛打了兴奋剂,进入高烧模式。层出不穷的刺激政策也必将持续影响房地产市场。中国人民银行决定,自2016年3月1日起,普遍下调金融机构人民币存款准备金率0.5个百分点。对于购房者来说,降准以后银行后续资金将更加宽裕,房贷有望继续宽松,购房者压力持续降低。  开年以来,在首付比例下降、税费下调等连续不断的楼市刺激政策推动下,一二线城市楼市异常火爆,而亟需去库存的三四线城市仍
Although using machine learning techniques to solve computer security challenges is not a new idea,the rapidly emerging Deep Learning technology has recently tr
交通基础设施作为区域经济发展的基本条件,是社会经济赖以发展的重要基础设施。随着社会经济的发展,交通基础设施的建设,缩小了资源流通的时空距离,扩大了社会经济活动的范围
目前,全国共青团的各级青年报刊已经发展到五十家,仅省一级的青年报刊就有三十七家,每期的发行总量在二千万份以上。这是一支重要的队伍。共青团的青年报刊既是党的喉舌又是
西部大开发是党和国家在世纪之交做出的一项重大战略决策。西部大开发战略所指的西部地区区域范围界定为12个省、区、市,即西北五省、区,西南五省、区、市,广西壮族自治区和
Command and control (C2) servers are used by attackers to operate communications.To perform attacks,attackers usually employee the Domain Generation Algorithm (