Preview

Труды Института системного программирования РАН

Расширенный поиск

Сравнительная количественная оценка механизмов усиления защищенности ядер операционных систем

https://doi.org/10.15514/ISPRAS-2026-38(4)-20

Аннотация

В работе предложена методика количественного сопоставления механизмов усиления защищенности ядер монолитных и микроядерных систем, а также встраиваемых операционных систем (ОС). Существующие руководства и инструменты обычно предназначены для отдельных операционных систем и позволяют проверить главным образом наличие механизмов и их включение; единая методика количественного сопоставления разнородных ядер отсутствует. Сформирована таксономия, включающая 76 механизмов, объединенных в семь категорий. Каждый механизм оценивается по пяти измерениям: наличию и применимости, использованию по умолчанию, стойкости реализации, степени архитектурной интеграции и зрелости. На основе частных оценок вычисляется интегральная оценка с учетом настраиваемых профилей весов измерений и весов категорий, определяемых моделью угроз. Интегральная оценка дополняется показателями охвата таксономии и качества реализованных механизмов, разделяющими широту и глубину защиты. Методика применена к девяти системам, представляющим три аналитические группы: Linux, OpenBSD, NetBSD, Fuchsia (Zircon), GNU Hurd (GNU Mach), seL4, Redox, Tock и Zephyr. Результаты показывают, что разброс оценок внутри одного архитектурного класса может превышать различия между классами. Следовательно, интегральная оценка зависит не только от архитектуры ядра, но и от полноты реализации механизмов, их использования по умолчанию, стойкости, зрелости и активности сопровождения. Полный набор данных с результатами оценки размещен в открытом доступе.

Об авторе

Денис Валентинович ЕФРЕМОВ
Институт системного программирования им. В.П. Иванникова РАН
Россия

Старший научный сотрудник. Сфера научных интересов: формальная верификация, статический и динамический анализ.



Список литературы

1. National Security Agency, Software Memory Safety. Cybersecurity Information Sheet, 2022. Available at: https://media.defense.gov/2022/Nov/10/2003112742/-1/-1/0/CSI_SOFTWARE_MEMORY_SAFETY.PDF, accessed 09.07.2026.

2. Szekeres L., Payer M., Tao Wei, Song D. SoK: Eternal War in Memory. In Proc. of the 2013 IEEE Symposium on Security and Privacy, 2013. pp. 48-62. DOI: 10.1109/SP.2013.13.

3. Cybersecurity and Infrastructure Security Agency, Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software. CISA and partner agencies, 2023. Available at: https://www.cisa.gov/resources-tools/resources/secure-by-design, accessed 09.07.2026.

4. Office of the National Cyber Director, Back to the Building Blocks: A Path Toward Secure and Measurable Software. The White House, Office of the National Cyber Director, 2024. Available at: https://bidenwhitehouse.archives.gov/wp-content/uploads/2024/02/Final-ONCD-Technical-Report.pdf, accessed 03.08.2026.

5. PaX Team, Address Space Layout Randomization. PaX project documentation, 2001. Available at: https://pax.grsecurity.net/docs/aslr.txt, accessed 03.08.2026.

6. de Raadt T. Exploit Mitigation Techniques in OpenBSD. OpenCON, presentation foils, 2005. Available at: https://www.openbsd.org/papers/ven05-deraadt/index.html, accessed 03.08.2026.

7. Evans C. Announcing Project Zero. Google Online Security Blog, 2014. Available at: https://security.googleblog.com/2014/07/announcing-project-zero.html, accessed 29.07.2026.

8. Kernel Self-Protection Project. Available at: https://kspp.github.io/, accessed 03.08.2026.

9. Kocher P., Horn J., Fogh A., Genkin D., Gruss D., Haas W., Hamburg M., Lipp M., Mangard S., Prescher T., Schwarz M., Yarom Y. Spectre Attacks: Exploiting Speculative Execution. In Proc. of the 2019 IEEE Symposium on Security and Privacy (SP), 2019. pp. 1-19. DOI: 10.1109/SP.2019.00002.

10. National Information Assurance Partnership, Protection Profile for General Purpose Operating Systems, Version 4.3. 2022. Available at: https://www.niap-ccevs.org/static_html/protection-profile/469/OS%204.3%20PP/index.html, accessed 03.08.2026.

11. Ефремов Д. В., Петренко А. К., Позин Б. А., Семенов В. А. Обзор механизмов усиления защищенности операционных систем и пользовательских приложений. Труды Института системного программирования РАН, 2025, том 37, вып. 3, стр. 325-354. DOI: 10.15514/ISPRAS-2025-37(3)-23. Available at: https://www.mathnet.ru/php/archive.phtml?wshow=paper&jrnid=tisp&paperid=1006&option_lang=eng, accessed 03.08.2026.

12. Center for Internet Security, CIS Benchmarks. Available at: https://www.cisecurity.org/cis-benchmarks, accessed 09.07.2026.

13. Defense Information Systems Agency, Security Technical Implementation Guides (STIGs). Available at: https://public.cyber.mil/stigs/, accessed 09.07.2026.

14. Popov A. kernel-hardening-checker: A tool for checking the security hardening options of the Linux kernel. 2024. Available at: https://github.com/a13xp0p0v/kernel-hardening-checker, accessed 09.07.2026.

15. Efremov D. V. OS Kernel Hardening Evaluation: Taxonomy, Evaluation Data and Scoring Pipeline. 2026. Available at: https://evdenis.github.io/os-hardening-evaluation/, accessed 29.07.2026.

16. Pendleton M., Garcia-Lebron R., Cho J., Xu S. A Survey on Systems Security Metrics. ACM Computing Surveys, 2016, vol. 49, issue 4, pp. 62:1-62:35. DOI: 10.1145/3005714.

17. Afzali H., Mokhtari H. A Quantitative Model of Operating System Security Evaluation. In Proc. of the Advances in Computer Science, Engineering & Applications, 2012. pp. 345-353. DOI: 10.1007/978-3-642-30111-7_33.

18. Song J., Hu G., Xu Q. Operating System Security and Host Vulnerability Evaluation. In Proc. of the 2009 International Conference on Management and Service Science, 2009. pp. 1-4. DOI: 10.1109/ICMSS.2009.5302077.

19. Cheng L., Zhang Y., Han Z., Deng Y., Sun X., Feng D. Evaluating and comparing the quality of access control in different operating systems. Computers & Security, 2014, vol. 47, pp. 26-40. DOI: 10.1016/j.cose.2014.05.001.

20. Chen S., Li D., Wu C., Zhan J. Evaluating Kernel Anti-Exploitation Capabilities: A Scalable and General Framework Based on Evaluatology. In Proc. of the Benchmarking, Measuring, and Optimizing – 16th BenchCouncil International Symposium, Bench 2024, 2025. pp. 127-143. DOI: 10.1007/978-981-96-5032-3_8.

21. Kurmus A., Tartler R., Dorneanu D., Heinloth B., Rothberg V., Ruprecht A., Schröder-Preikschat W., Lohmann D., Kapitza R. Attack Surface Metrics and Automated Compile-Time OS Kernel Tailoring. In Proc. of the 20th Annual Network and Distributed System Security Symposium (NDSS), 2013. Available at: https://www.ndss-symposium.org/ndss2013/attack-surface-metrics-and-automated-compile-time-os-kernel-tailoring.

22. Enoch S. Y., Moon C. Y., Lee D., Ahn M. K., Kim D. S. A Practical Framework for Cyber Defense Generation, Enforcement and Evaluation. Computer Networks, 2022, vol. 208, pp. 108878. DOI: 10.1016/j.comnet.2022.108878.

23. Lim S. Y., Agrawal S., Han X., Eyers D., O'Keeffe D., Pasquier T. Securing Monolithic Kernels using Compartmentalization. 2024. arXiv:2404.08716.

24. Lefeuvre H., Dautenhahn N., Chisnall D., Olivier P. SoK: Software Compartmentalization. In Proc. of the 46th IEEE Symposium on Security and Privacy (S&P), 2025. pp. 3107-3126. DOI: 10.1109/SP61157.2025.00075.

25. Guo Y., Wang Z., Bai W., Zeng Q., Lu K. BULKHEAD: Secure, Scalable, and Efficient Kernel Compartmentalization with PKS. In Proc. of the 32nd Annual Network and Distributed System Security Symposium (NDSS), 2025. DOI: 10.14722/ndss.2025.230328.

26. Klein G., Andronick J., Elphinstone K., Murray T., Sewell T., Kolanski R., Heiser G. Comprehensive Formal Verification of an OS Microkernel. ACM Transactions on Computer Systems, 2014, vol. 32, issue 1, pp. 2:1-2:70. DOI: 10.1145/2560537.

27. Gruss D., Lipp M., Schwarz M., Fellner R., Maurice C., Mangard S. KASLR is Dead: Long Live KASLR. In Proc. of the Engineering Secure Software and Systems (ESSoS 2017), 2017. pp. 161-176. DOI: 10.1007/978-3-319-62105-0_11.

28. Yoo S., Park J., Kim S., Kim Y., Kim T. In-Kernel Control-Flow Integrity on Commodity OSes using ARM Pointer Authentication. In Proc. of the 31st USENIX Security Symposium, 2022. pp. 89-106. Available at: https://www.usenix.org/conference/usenixsecurity22/presentation/yoo.

29. Liakh S., Grace M., Jiang X. Analyzing and Improving Linux Kernel Memory Protection: A Model Checking Approach. In Proc. of the 26th Annual Computer Security Applications Conference (ACSAC), 2010. pp. 271-280. DOI: 10.1145/1920261.1920301.

30. Rauscher F., Herzog B., Hönig T., Gruss D. Systematic Analysis of Kernel Security Performance and Energy Costs. In Proc. of the 20th ACM Asia Conference on Computer and Communications Security, 2025. pp. 1676-1689. DOI: 10.1145/3708821.3736197.

31. Bhat P., Dutta K. A Survey on Various Threats and Current State of Security in Android Platform. ACM Computing Surveys, 2019, vol. 52, issue 1, pp. 21:1-21:35. DOI: 10.1145/3301285.

32. Ahmed O. M., Sallow A. B. Android Security: A Review. Academic Journal of Nawroz University, 2017, vol. 6, issue 3, pp. 135-140. DOI: 10.25007/ajnu.v6n3a97.

33. Zakaria S. N., Zolkipli M. F. Review on Mobile Attacks: Operating System, Threats, and Solution. Borneo International Journal, 2021, vol. 4, issue 2, pp. 8-16.

34. Cybersecurity and Infrastructure Security Agency, Vulnrichment: CVE enrichment with CWE, CVSS and SSVC decision points. 2024. Available at: https://github.com/cisagov/vulnrichment, accessed 02.08.2026.

35. MITRE Corporation, 2025 CWE Top 25 Most Dangerous Software Weaknesses. 2025. Available at: https://cwe.mitre.org/top25/, accessed 02.08.2026.

36. Google Project Zero, 0-days In-the-Wild: root cause analyses and tracking spreadsheet. Available at: https://googleprojectzero.github.io/0days-in-the-wild/, accessed 02.08.2026.

37. Shameli-Sendi A. Understanding Linux kernel vulnerabilities. Journal of Computer Virology and Hacking Techniques, 2021, vol. 17, issue 4, pp. 265-278. DOI: 10.1007/s11416-021-00379-x.

38. de Raadt T. KARL - Kernel Address Randomized Link. 2017. Available at: https://marc.info/?l=openbsd-tech&m=149732026405941&w=2, accessed 17.06.2025.

39. de Raadt T. Amd64 Kernel W^X. 2015. Available at: https://marc.info/?l=openbsd-tech&m=142120787308107&w=2, accessed 17.06.2025.

40. Ge Q., Yarom Y., Chothia T., Heiser G. Time Protection: The Missing OS Abstraction. In Proc. of the Fourteenth EuroSys Conference (EuroSys '19), 2019. DOI: 10.1145/3302424.3303976.

41. Miller T. C., de Raadt T. strlcpy and strlcat – Consistent, Safe, String Copy and Concatenation. In Proc. of the USENIX Annual Technical Conference, FREENIX Track, 1999. Available at: https://www.usenix.org/legacy/publications/library/proceedings/usenix99/full_papers/millert/millert.pdf, accessed 03.08.2026.

42. Kettenis M. Disable SMT (Simultaneous Multi-Threading) by default and introduce the hw.smt sysctl. OpenBSD src repository, commit 96c1135, 2018. Available at: https://github.com/openbsd/src/commit/96c11352863a7f6240b4e5e388052f414b75f95b, accessed 02.08.2026.

43. Varghese S. OpenBSD's de Raadt slams Red Hat, Canonical over 'secure' boot. iTWire, interview with Theo de Raadt, 2012. Available at: https://itwire.com/business-it-news/open-source/openbsds-de-raadt-slams-red-hat-canonical-over-secure-boot, accessed 03.08.2026.

44. Unangst T. Re: veriexec in OpenBSD?. Post to the openbsd-misc mailing list, 2010. Available at: https://marc.info/?l=openbsd-misc&m=128337583106955&w=2, accessed 02.08.2026.

45. Guenther P. Re: Verified Executables for OpenBSD?. Post to the openbsd-misc mailing list, 2016. Available at: https://marc.info/?l=openbsd-misc&m=147327081816169&w=2, accessed 02.08.2026.

46. Unangst T. signify: Securing OpenBSD From Us To You. BSDCan, 2015. Available at: https://www.openbsd.org/papers/bsdcan-signify.html, accessed 02.08.2026.


Рецензия

Для цитирования:


ЕФРЕМОВ Д.В. Сравнительная количественная оценка механизмов усиления защищенности ядер операционных систем. Труды Института системного программирования РАН. 2026;38(4):81-108. https://doi.org/10.15514/ISPRAS-2026-38(4)-20

For citation:


EFREMOV D.V. Comparative Quantitative Evaluation of Kernel Hardening Mechanisms in Operating Systems. Proceedings of the Institute for System Programming of the RAS (Proceedings of ISP RAS). 2026;38(4):81-108. (In Russ.) https://doi.org/10.15514/ISPRAS-2026-38(4)-20



Creative Commons License
Контент доступен под лицензией Creative Commons Attribution 4.0 License.


ISSN 2079-8156 (Print)
ISSN 2220-6426 (Online)