Feedback

Faculté des Sciences appliquées
Faculté des Sciences appliquées
MASTER THESIS
VIEW 123 | DOWNLOAD 14

Master thesis : Integrating address space layout randomization and make it compatible with memory de-duplication in Unikraft

Download
Loslever, Terry ULiège
Promotor(s) : Mathy, Laurent ULiège ; Gain, Gaulthier ULiège
Date of defense : 27-Jun-2022/28-Jun-2022 • Permalink : http://hdl.handle.net/2268.2/14572
Details
Title : Master thesis : Integrating address space layout randomization and make it compatible with memory de-duplication in Unikraft
Translated title : [fr] Intégrer la distribution aléatoire de l'espace d'adressage dans Unikraft et la rendre compatible avec la déduplication mémoire.
Author : Loslever, Terry ULiège
Date of defense  : 27-Jun-2022/28-Jun-2022
Advisor(s) : Mathy, Laurent ULiège
Gain, Gaulthier ULiège
Committee's member(s) : Boigelot, Bernard ULiège
Donnet, Benoît ULiège
Language : English
Number of pages : 67
Discipline(s) : Engineering, computing & technology > Computer science
Target public : Researchers
Professionals of domain
Student
Institution(s) : Université de Liège, Liège, Belgique
Degree: Master : ingénieur civil en informatique, à finalité spécialisée en "computer systems security"
Faculty: Master thesis of the Faculté des Sciences appliquées

Abstract

[en] During the past years, people's online services usage kept growing which increases the load on the servers of cloud services and content distribution network. Those servers often run on containers that run on top of monolithic operating systems or simply on monolithic operating systems which embarks libraries, abstractions and codes that may nor be needed nor be used by the application it runs.

Unikernels give the opportunity to the developer to build a specific operating system that contains only features that will be further used by the application and run it directly on top of the hypervisor. Furthermore, simplifying the operating system, on which the application runs, often results in a performance gain.

However, if unikernels were to be used more frequently by the industry, we have to be certain that they are as secure as the other technologies available on the market. Throughout this thesis, we have implemented address space layout randomization inside Unikraft in order to make memory related vulnerabilities harder to exploit.

Nevertheless, address space layout randomization comes at a cost which is its memory usage. We addressed that problem and found a way to mitigate the overhead : through page sharing between the unikernels thanks to indirection tables, which were implemented in two different manners. In the first, problematic instructions were set in a table that is appended directly to its corresponding library while the second creates a global table at a specified address that holds instructions from every libraries. Gaulthier Gain, the co-supervisor of this thesis, implemented the appended method thus this thesis addresses the implementation of the global table and the comparison between the two manners.

Finally, we compared the performances of our address space layout randomization with Unikraft's previous implementation of it, and we discussed the two indirection methods. We came to the conclusion that the appended tables gave satisfying results when there was enough images running on the hypervisor, while the other was not giving any memory savings due to the constraints induced by the x86 64 bits CPU architecture.


File(s)

Document(s)

File
Access TFE.pdf
Description:
Size: 2.91 MB
Format: Adobe PDF
File
Access Abstract.pdf
Description:
Size: 90.77 kB
Format: Adobe PDF

Author

  • Loslever, Terry ULiège Université de Liège > Master ingé. civ. info., à fin.

Promotor(s)

Committee's member(s)

  • Boigelot, Bernard ULiège Université de Liège - ULiège > Dép. d'électric., électron. et informat. (Inst.Montefiore) > Informatique
    ORBi View his publications on ORBi
  • Donnet, Benoît ULiège Université de Liège - ULiège > Dép. d'électric., électron. et informat. (Inst.Montefiore) > Algorithmique des grands systèmes
    ORBi View his publications on ORBi
  • Total number of views 123
  • Total number of downloads 14










All documents available on MatheO are protected by copyright and subject to the usual rules for fair use.
The University of Liège does not guarantee the scientific quality of these students' works or the accuracy of all the information they contain.