AppShield: Protecting Applications Against Untrusted Operating System
Yueqiang Cheng, Xuhua Ding, Robert Huijie Deng · 2013
Commodity operating systems are known to be vulnerable to rootkit attacks due to their enormous code base and complex logic. Since the OS runs with a higher privilege than user applications, the rootkit residing in the kernel can access the entire user application space, even when the application is designed and implemented with security considerations. Existing systems protecting user-space code have various drawbacks, such as high performance overhead, large Trusted Computing Base (TCB), hardware modifications, or with a restriction imposed on the protected code. Moreover, several newly identified threats in our paper are evidence that protecting applications from malicious OS is more challenging than previously realized. In this paper, we present the design and implementation of AppShield, a hypervisor-based approach that efficiently and reliably safeguards code, data and execution integrity of a critical application. The protection overhead is localized to the protected application such that unprotected applications are not affected. We implement the prototype of AppShield with a tiny hypervisor. We experiment AppShield with several existing applications on a Linux platform and the results show that the performance costs on CPU computation, disk I/O and network I/O are insignificant.