XFI: Software guards for system address spaces

323Citations
Citations of this article
157Readers
Mendeley users who have this article in their library.

Abstract

XFI is a comprehensive protection system that offers both flexible access control and fundamental integrity guarantees, at any privilege level and even for legacy code in commodity systems. For this purpose, XFI combines static analysis with inline software guards and a two-stack execution model. We have implemented XFI for Windows on the x86 architecture using binary rewriting and a simple, stand-alone verifier; the implementation’s correctness depends on the verifier, but not on the rewriter. We have applied XFI to software such as device drivers and multimedia codecs. The resulting modules function safely within both kernel and user-mode address spaces, with only modest enforcement overheads.

Cite

CITATION STYLE

APA

Erlingsson, Ú., Abadi, M., Vrable, M., Budiu, M., & Necula, G. C. (2006). XFI: Software guards for system address spaces. In OSDI 2006 - 7th USENIX Symposium on Operating Systems Design and Implementation (pp. 75–88). USENIX Association.

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free