{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/50547"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/50547","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Secure virtual architecture: security for commodity software systems","abstract":"Commodity operating systems are entrusted with providing security to the applications we use everyday, and yet they suffer from the same security vulnerabilities as user-space applications: they are susceptible to memory safety attacks such as buffer overflows, and they can be tricked into dynamically loading malicious code. Worse yet, commodity operating system kernels are highly privileged; exploitation of the kernel results in compromise of all applications on the system. This work describes the Secure Virtual Architecture (SVA): a compiler-based virtual machine placed between the software stack and the hardware that can enforce strong security policies on commodity application and operating system kernel code. This work describes how SVA abstracts hardware/software interactions and program state manipulation so that compiler instrumentation can be used to control these operations, and it shows how SVA can be used to protect both the operating system kernel and applications from attack. Specifically, this work shows how SVA can protect operating system kernels from memory safety attacks; it also shows how SVA prevents a compromised operating system kernel from adversely affecting the execution of trusted applications by providing application memory that the operating system kernel cannot read and write and secure application control flow that the operating system cannot corrupt.","abstract_html":"Commodity operating systems are entrusted with providing security to the applications we use everyday, and yet they suffer from the same security vulnerabilities as user-space applications: they are susceptible to memory safety attacks such as buffer overflows, and they can be tricked into dynamically loading malicious code. Worse yet, commodity operating system kernels are highly privileged; exploitation of the kernel results in compromise of all applications on the system. This work describes the Secure Virtual Architecture (SVA): a compiler-based virtual machine placed between the software stack and the hardware that can enforce strong security policies on commodity application and operating system kernel code. This work describes how SVA abstracts hardware/software interactions and program state manipulation so that compiler instrumentation can be used to control these operations, and it shows how SVA can be used to protect both the operating system kernel and applications from attack. Specifically, this work shows how SVA can protect operating system kernels from memory safety attacks; it also shows how SVA prevents a compromised operating system kernel from adversely affecting the execution of trusted applications by providing application memory that the operating system kernel cannot read and write and secure application control flow that the operating system cannot corrupt.","abstract_has_math":false,"creators":["Criswell, John"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Adve, Vikram S.","Parthasarathy, Madhusudan","King, Samuel T.","Morrisett, Greg"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2014,"date_issued":"2014-09-16T17:23:42Z","date_published":"2014-09-16T17:23:42Z","updated_at":"2026-07-22T22:25:40Z","subjects":["secure virtual architecture","computer security","security","compilers","operating systems","LLVM compiler infrastructure project","Low Level Virtual Architecture (LLVA)","Secure Virtual Architecture (SVA)","(Kernel Control Flow Integrity (KCoFI)","Virtual Ghost","memory safety","control flow integrity","compromised operating systems"],"languages":["en"],"rights":["Copyright 2014 John T Criswell"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/50547","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Adve, Vikram S.","Parthasarathy, Madhusudan","King, Samuel T.","Morrisett, Greg"]},{"key":"dc:creator","label":"Author","values":["Criswell, John"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2014-09-16T17:23:42Z","2014-08","2014-09-16"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["secure virtual architecture","computer security","security","compilers","operating systems","LLVM compiler infrastructure project","Low Level Virtual Architecture (LLVA)","Secure Virtual Architecture (SVA)","(Kernel Control Flow Integrity (KCoFI)","Virtual Ghost","memory safety","control flow integrity","compromised operating systems"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2014 John T Criswell"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/50547"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Commodity operating systems are entrusted with providing security to the applications we use everyday, and yet they suffer from the same security vulnerabilities as user-space applications: they are susceptible to memory safety attacks such as buffer overflows, and they can be tricked into dynamically loading malicious code. Worse yet, commodity operating system kernels are highly privileged; exploitation of the kernel results in compromise of all applications on the system. This work describes the Secure Virtual Architecture (SVA): a compiler-based virtual machine placed between the software stack and the hardware that can enforce strong security policies on commodity application and operating system kernel code. This work describes how SVA abstracts hardware/software interactions and program state manipulation so that compiler instrumentation can be used to control these operations, and it shows how SVA can be used to protect both the operating system kernel and applications from attack. Specifically, this work shows how SVA can protect operating system kernels from memory safety attacks; it also shows how SVA prevents a compromised operating system kernel from adversely affecting the execution of trusted applications by providing application memory that the operating system kernel cannot read and write and secure application control flow that the operating system cannot corrupt.","Item withdrawn by Laura Spradlin (lspradl2@illinois.edu) on 2014-07-14T16:01:55Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Criswell_John.pdf: 2841143 bytes, checksum: d38bc6a9f28402f131321d44b65f3a55 (MD5)","Made available in DSpace on 2014-09-16T17:23:42Z (GMT). No. of bitstreams: 2 John_Criswell.pdf: 2841067 bytes, checksum: ba526c20ede02bbe2d22b0cb4dabf357 (MD5) license.txt: 4063 bytes, checksum: 32588c911bab7e422f070a1f08b26f8f (MD5)"]},{"key":"dc:title","label":"Title","values":["Secure virtual architecture: security for commodity software systems"]}]}],"canonical_facts":{"dc:contributor":["Adve, Vikram S.","Parthasarathy, Madhusudan","King, Samuel T.","Morrisett, Greg"],"dc:creator":["Criswell, John"],"dc:date":["2014-09-16T17:23:42Z","2014-08","2014-09-16"],"dc:description":["Commodity operating systems are entrusted with providing security to the applications we use everyday, and yet they suffer from the same security vulnerabilities as user-space applications: they are susceptible to memory safety attacks such as buffer overflows, and they can be tricked into dynamically loading malicious code. Worse yet, commodity operating system kernels are highly privileged; exploitation of the kernel results in compromise of all applications on the system. This work describes the Secure Virtual Architecture (SVA): a compiler-based virtual machine placed between the software stack and the hardware that can enforce strong security policies on commodity application and operating system kernel code. This work describes how SVA abstracts hardware/software interactions and program state manipulation so that compiler instrumentation can be used to control these operations, and it shows how SVA can be used to protect both the operating system kernel and applications from attack. Specifically, this work shows how SVA can protect operating system kernels from memory safety attacks; it also shows how SVA prevents a compromised operating system kernel from adversely affecting the execution of trusted applications by providing application memory that the operating system kernel cannot read and write and secure application control flow that the operating system cannot corrupt.","Item withdrawn by Laura Spradlin (lspradl2@illinois.edu) on 2014-07-14T16:01:55Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Criswell_John.pdf: 2841143 bytes, checksum: d38bc6a9f28402f131321d44b65f3a55 (MD5)","Made available in DSpace on 2014-09-16T17:23:42Z (GMT). No. of bitstreams: 2 John_Criswell.pdf: 2841067 bytes, checksum: ba526c20ede02bbe2d22b0cb4dabf357 (MD5) license.txt: 4063 bytes, checksum: 32588c911bab7e422f070a1f08b26f8f (MD5)"],"dc:identifier":["http://hdl.handle.net/2142/50547"],"dc:language":["en"],"dc:rights":["Copyright 2014 John T Criswell"],"dc:subject":["secure virtual architecture","computer security","security","compilers","operating systems","LLVM compiler infrastructure project","Low Level Virtual Architecture (LLVA)","Secure Virtual Architecture (SVA)","(Kernel Control Flow Integrity (KCoFI)","Virtual Ghost","memory safety","control flow integrity","compromised operating systems"],"dc:title":["Secure virtual architecture: security for commodity software systems"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:40Z"}