Granary: Comprehensive Kernel Module Instrumentation
Peter Goodman, Angela Demke Brown, Akshay Kumar V, Ashvin Goel · 2012
Kernel modules extend the functionality of operating systems (OSes). Modules are used to support new devices (e.g. network and graphics cards) and provide new features (e.g. file systems). The kernel and its modules execute in a complex and dynamic environment. Understanding how modules behave in and affect this environment is important. However, analyzing module behavior is challenging. Static analysis of module source code is difficult because of the tight interaction between modules and the kernel. Some modules, however, are only distributed in a binary format, which makes static analysis intractable. We created Granary to address the challenges of module analysis. Granary is a framework that efficiently instruments arbitrary, binary Linux kernel modules. Granary uses dynamic binary translation to dynamically rewrite and comprehensively instrument kernel modules. Our extensive use of compile-time meta-programming enables efficient, dynamic analyses that are driven by static kernel type information. While designing Granary, we identified four goals for practical module analysis: i) comprehensively analyze all modules; ii) impose no performance overheads on nonmodule kernel code; iii) require no changes to modules and minimal changes to the kernel, and; iv) be easily portable between different hardware and kernel versions. Prior research based on source code analysis and annotations [2] fails to meet goals (i) and (iii), while work based on special hardware features or virtualization [3] fails to meet goals (i) and (iv), and work based on whole-OS or -system instrumentation/emulation [1] fails to meet goal (ii). Granary meets all four stated goals: