An approach to improve the reliability of the host machines with driver isolation is proposed to solve the problem that the driver fault crashes the host machines and its virtual machines. The approach is based on the protection domain of the pre-developed architecture StyleBox and extends it to isolate the driver with complex interfaces. For detail
it creates wrapper functions for the complex interactive interfaces between the driver and the kernel
limits the driver running in the protection domain
and provides private memories for isolated drivers to support the driver's normal operation in the protection domain. Experimental results on a Linux2.6.28.10 host machine kernel that is modified using the proposed approach show that the approach successfully detects 90.63% of the faults
which are randomly injected to the network driver and damage the host machines kernel
and isolates 67.5% of them
and that the reliability of host machines is improved.
关键词
Keywords
references
SWIFT M M, BERSHAD B N, LEVY H M. Improving the reliability of commodity operating systems [J]. ACM Transactions on Computer Systems, 2005, 23(1): 77-110.
LEVASSEUR J, UHLIG V, STOESS J, et al. Unmodified device driver reuse and improved system dependability via virtual machines [C]∥Proceedings of the 6th USENIX Symposium on Operating Systems Design and Implementation. Berkeley, CA, USA: USENIX, 2004: 17-30.
TAN L, CHAN E M, FARIVAR R, et al. iKernel: isolating buggy and malicious device drivers using hardware virtualization support [C]∥Proceedings of the Third IEEE International Symposium on Dependable, Autonomic and Secure Computing. Piscataway, NJ, USA: IEEE, 2007: 134-144.
GANAPATHY V, RENZELMANN M J, BALAKRISHNAN A, et al. The design and implementation of microdrivers [J]. ACM SIGOPS Operating Systems Review, 2008, 42(2): 168-178.
WILLIANS D, REYNOLDS P, WALSH K, et al. Device driver safety through a reference validation mechanism [C]∥Proceedings of the 8th USENIX Symposium on Operating Systems Design and Implementation. Berkeley, CA, USA: USENIX, 2008: 241-254.
HUA Baojian, CHEN Yiyun, LI Zhaopeng, et al. Design and proof of a safe programming language PointerC [J]. Chinese Journal of Computers, 2008, 31(4): 556-564.
ZHOU F, CONDIT J, ANDERSON Z, et al. SafeDrive: safe and recoverable extensions using language-based techniques [C]∥Proceedings of the 7th USENIX Symposium on Operating Systems Design and Implementation. Berkeley, CA, USA: USENIX, 2006: 45-60.
CASTRO M, COSTA M, MARTIN J, et al. Fast byte-granularity software fault isolation [C]∥Proceedings of the ACM SIGOPS 22nd Symposium on Operating Systems Principles. New York, USA: ACM, 2009: 45-58.
ZHENG Hao, ZHANG Xinjun, WANG Endong, et al. Achieving High Reliability on Linux for K2 System [C]∥Proceedings of the 2012 IEEE/ACIS 11th International Conference on Computer and Information Science. Piscataway, NJ, USA: IEEE, 2012: 107-112.