GyroidOS
Felix Wruck, Vasil Sarafov, Florian Jakobsmeier, Michael Weiß · 2022
Separation of privilege domains is crucial when building secure system architectures for Cyber-Physical systems. The bar for a successful attack can be raised significantly and the consequences of an attack can be contained. As Cyber-physical systems often comprise devices with limited resources, container virtualization provides an ideal base technology to construct secure architectures for CPS. However, the provided isolation guarantees entirely depend on one, shared kernel. Therefore, it is crucial to protect this kernel against attacks. Recent research proposed solutions to this issue. However, these approaches incurred performance penalties hindering their practical applicability. Therefore, we created GyroidOS, an architecture to shrink the kernel attack surface available to an attacker inside a container. To achieve this, we exploit redundancy in the Linux syscall interface to restrict access to syscalls without reducing the functionality available to user space binaries. Thereby, we aim to achieve maximum compatibility and applicability in real world scenarios. At the same time, GyroidOS aims to minimize the imposed performance penalty to avoid performance-related issues in the applicability of which previous approaches suffered.