Back to results

University of Illinois at Urbana-Champaign

Protection in commodity monolithic operating systems

Abstract

dc:description

"This dissertation suggests and partially demonstrates that it is feasible to retrofit real privilege separation within commodity operating systems by ""nesting"" a small memory management protection domain inside a monolithic kernel's single-address space: all the while allowing both domains to operate at the same hardware privilege level. This dissertation also demonstrates a microarchitectural return-integrity protection domain that efficiently asserts dynamic ""return-to-sender"" semantics for all operating system return control-flow operations. Employing these protection domains, we provide mitigations to large classes of kernel attacks such as code injection and return-oriented programming and deploy information protection policies that are not feasible with existing systems. Operating systems form the foundation of information protection in multiprogramming environments. Unfortunately, today's commodity operating systems employ monolithic kernel design, where any single exploit in the vast code base undermines all information protection in the system because all kernel code operates with full supervisor privileges, meaning that even perfectly secure applications are vulnerable. This dissertation explores an approach that retrofits fundamental information protection design principles into commodity monolithic operating systems, the aim of which is a micro-evolution of commodity system design that incrementally decomposes monolithic operating systems from the ground up, thereby applying microkernel-like security properties for billions of users worldwide. The key contribution is the creation of a new operating system organization, the Nested Kernel Architecture, which ""nests"" a new, efficient intra-kernel memory isolation mechanism into a traditional monolithic operating system design. Using the Nested Kernel Architecture we introduce write-protection services for kernel developers to deploy security policies in ways not possible in current systems—while greatly reducing the trusted computing base—and demonstrate the value of these services by deploying three special data protection policies. Overall, the Nested Kernel Architecture demonstrates practical in-place protections that require only minor code modifications with minimal run- time overheads."

Degree

thesis:*
Name thesis:degree_name
Ph.D.
Level thesis:degree_level
Dissertation
Discipline thesis:degree_discipline
Computer Science
Grantor
University of Illinois at Urbana-Champaign
Year dc:date
2016

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Dautenhahn, Nathan D
Contributors dc:contributor
  • Adve, Vikram
  • Nahrstedt, Klara
  • Gunter, Carl A.
  • Bugnion, Edouard
  • King, Samuel T.

Subjects

dc:subject × 7

Rights

dc:rights
Statement dc:rights
  • Copyright 2016 by Nathan Daniel Dautenhahn. All rights reserved.
Language dc:language
en

Identifiers

dc:identifier.*
Handle dc:identifier
http://hdl.handle.net/2142/92699
OAI identifier oai:identifier
oai:www.ideals.illinois.edu:2142/92699

Chain of custody

source
Harvested from
University of Illinois - Urbana-Champaign
Base URL
www.ideals.illinois.edu/oai-pmh
Last updated
2026-07-22
Source record
OAI-PMH GetRecord
citation

Dautenhahn, Nathan D. Protection in commodity monolithic operating systems. Dissertation thesis, University of Illinois at Urbana-Champaign, 2016. http://hdl.handle.net/2142/92699