Enclaves for operating system protection
Jacob Torrey, Brent Sherman · 2016
As networks become increasingly targeted by attackers in search of sensitive data, a new data protection model is arising — one in which data aims to be protected even on contested networks. In this new paradigm, a stronger isolation boundary is needed than the current process model of the status quo affords — hardware-enforced enclaves are a step towards true data protection in contested networks. This paper provides a background of enclaves through two example implementations: HARES and Intel SGX, followed by three example case studies of well-known malware that could have been prevented through the deployment of enclave technologies. Finally a discussion on the weaknesses of the current enclave technologies is provided before concluding remarks.