3 ms·
Says it's secure, Github shows 76% of the code is in C. I see the word "secure" in a few places but it's just stated without any indication as to what about thi
by staticassertion 5y ago
Says it's secure, Github shows 76% of the code is in C. I see the word "secure" in a few places but it's just stated without any indication as to what about this makes it secure.
- nderjung 5y agoUnikraft is based on a small trusted compute base, meaning there is nothing else running with a unikernel, no ssh, no daemons, no Linux, etc. Towards increasing security, however, we have just introduced native support for Rust[0] in Unikraft, paving the way for more internal libraries to be based on this secure and performant language. [0]: https://github.com/unikraft/unikraft/pull/348 https://github.com/unikraft/unikraft/pull/348
- staticassertion 5y agoThanks, I think having a "read more" would be helpful. You do a good job of quickly demonstrating performance with some numbers, but there's nothing about security on there. I think it'd go a long way for people like me who are going to be immediately skeptical of software in C claiming to be safe.
- nderjung 5y agoThanks for the feedback, we're in the process of adding a security section[0] which will detail more on the on-goings, but we'll work on adding more highlights on the main page. I need to highlight we have separate research[1][2] which will make its way upstream soon which aims to provide hardening between internal libraries (e.g. isolating the network stack or scheduler) using gates like Intel MPK or separate hardware-accelerated services. [0]: https://github.com/unikraft/docs/pull/32 https://github.com/unikraft/docs/pull/32 [1]: https://project-flexos.github.io/ https://project-flexos.github.io/ [2]: https://github.com/project-flexos/unikraft https://github.com/project-flexos/unikraft
- staticassertion 5y agoPretty cool, will definitely read through that.
- fulafel 5y agoHow does the system tolerate vulnerabilities outside the TCB? I thought unikernels often didn't have protections that would shield a TCB from app vulnerabilities.
- convolvatron 5y agowhat are you trying to protect the kernel for if it only hosts in the single application? are you assuming that local root has some distinguished privilege outside this box?
- fulafel 5y agoGood question, I assume there was some reason to talk about a TCB and the answer might have shed light on that as well.
- felipehuici 5y agoHi, no, the statement wasn't to isolate the kernel code from the application, since it's all in the same address space. Instead, it's to reduce the possibility of bugs (but again, not in the application), and reduce the vectors for attack in the underlying stack. For separating the application from the kernel (and from components within the kernel, since Unikraft is modular) we are doing further work called FlexOS, based on Unikraft, and to appear soon at the ASPLOS conference[0]; a short version of the paper appeared at HotOS [1]. [0] https://asplos-conference.org/program/ https://asplos-conference.org/program/ [1]https://sigops.org/s/conferences/hotos/2021/papers/hotos21-s05-lefeuvre.pdf https://sigops.org/s/conferences/hotos/2021/papers/hotos21-s...
- fulafel 5y agoInteresting! I found also this paper that talks about estabilishing a TCB in the unikernel which was a good companion read. https://www.ssrg.ece.vt.edu/papers/spma20.pdf https://www.ssrg.ece.vt.edu/papers/spma20.pdf