{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T12:18:34Z","timestamp":1763468314261,"version":"3.41.0"},"reference-count":58,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2015,12,8]],"date-time":"2015-12-08T00:00:00Z","timestamp":1449532800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100008982","name":"Qatar National Research Fund","doi-asserted-by":"publisher","award":["4-1593-1-260"],"award-info":[{"award-number":["4-1593-1-260"]}],"id":[{"id":"10.13039\/100008982","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Archit. Code Optim."],"published-print":{"date-parts":[[2016,1,7]]},"abstract":"<jats:p>The inclusive permissions structure (e.g., the Intel ring model) of modern commodity CPUs provides privileged system software layers with arbitrary permissions to access and modify client processes, allowing them to manage these clients and the system resources efficiently. Unfortunately, these inclusive permissions allow a compromised high-privileged software layer to perform arbitrary malicious activities. In this article, our goal is to prevent attacks that cross system layers while maintaining the abilities of system software to manage the system and allocate resources. In particular, we present a hardware-supported page permission framework for physical pages that is based on the concept of noninclusive sets of memory permissions for different layers of system software (such as hypervisors, operating systems, and user-level applications). Instead of viewing privilege levels as an ordered hierarchy with each successive level being more privileged, we view them as distinct levels each with its own set of permissions. In order to enable system software to manage client processes, we define a set of legal permission transitions that support resource allocation but preserve security. We show that the model prevents a range of recent attacks. We also show that it can be implemented with negligible performance overhead (both at load time and at runtime), low hardware complexity, and minimal changes to the commodity OS and hypervisor code.<\/jats:p>","DOI":"10.1145\/2842621","type":"journal-article","created":{"date-parts":[[2015,12,10]],"date-time":"2015-12-10T14:22:10Z","timestamp":1449757330000},"page":"1-27","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Rethinking Memory Permissions for Protection Against Cross-Layer Attacks"],"prefix":"10.1145","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6679-1624","authenticated-orcid":false,"given":"Jesse","family":"Elwell","sequence":"first","affiliation":[{"name":"SUNY Binghamton"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ryan","family":"Riley","sequence":"additional","affiliation":[{"name":"Qatar University, Doha, Qatar"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nael","family":"Abu-Ghazaleh","sequence":"additional","affiliation":[{"name":"University of California, Riverside"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dmitry","family":"Ponomarev","sequence":"additional","affiliation":[{"name":"SUNY Binghamton"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Iliano","family":"Cervesato","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University, Doha, Qatar"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2015,12,8]]},"reference":[{"volume-title":"Proceedings of the Workshop on Hardware and Architectural Support for Security and Privacy, with ISCA \u201913","author":"Anati I.","key":"e_1_2_1_1_1","unstructured":"I. Anati , S. Gueron , S. Johnson , and V. Scarlata . 2013. Innovative technology for CPU based attestation and sealing . In Proceedings of the Workshop on Hardware and Architectural Support for Security and Privacy, with ISCA \u201913 . I. Anati, S. Gueron, S. Johnson, and V. Scarlata. 2013. Innovative technology for CPU based attestation and sealing. In Proceedings of the Workshop on Hardware and Architectural Support for Security and Privacy, with ISCA \u201913."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2009.50"},{"volume-title":"Proceedings of the Symposium on Operating Systems Design and Implementation.","author":"Baumann A.","key":"e_1_2_1_3_1","unstructured":"A. Baumann , M. Peinado , and G. Hunt . 2014. Shielding applications from an untrusted cloud with haven . In Proceedings of the Symposium on Operating Systems Design and Implementation. A. Baumann, M. Peinado, and G. Hunt. 2014. Shielding applications from an untrusted cloud with haven. In Proceedings of the Symposium on Operating Systems Design and Implementation."},{"key":"e_1_2_1_4_1","unstructured":"R. Boivie. 2012. SecureBlue++: CPU Support for Secure Execution. (2012).  R. Boivie. 2012. SecureBlue++: CPU Support for Secure Execution. (2012)."},{"volume-title":"1st Benelux Workshop on Information Systems Security.","author":"Cappaert J.","key":"e_1_2_1_5_1","unstructured":"J. Cappaert , N. Kisserli , D. Schellekens , and B. Preneel . 2006. Self-encrypting code to protect against analysis and tampering . In 1st Benelux Workshop on Information Systems Security. J. Cappaert, N. Kisserli, D. Schellekens, and B. Preneel. 2006. Self-encrypting code to protect against analysis and tampering. In 1st Benelux Workshop on Information Systems Security."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/195470.195579"},{"volume-title":"Proceedings of the International Symposium on High Performance Computer Architecture.","author":"Champagne D.","key":"e_1_2_1_7_1","unstructured":"D. Champagne and R. Lee . 2010. Scalable architectural support for trusted software . In Proceedings of the International Symposium on High Performance Computer Architecture. D. Champagne and R. Lee. 2010. Scalable architectural support for trusted software. In Proceedings of the International Symposium on High Performance Computer Architecture."},{"volume-title":"Proceedings of the 14th Conference on USENIX Security Symposium. USENIX Association","author":"Chen S.","key":"e_1_2_1_8_1","unstructured":"S. Chen , J. Xu , E. C. Sezer , P. Gauriar , and R. K. Iyer . 2005. Non-control-data attacks are realistic threats . In Proceedings of the 14th Conference on USENIX Security Symposium. USENIX Association , Berkeley, CA. S. Chen, J. Xu, E. C. Sezer, P. Gauriar, and R. K. Iyer. 2005. Non-control-data attacks are realistic threats. In Proceedings of the 14th Conference on USENIX Security Symposium. USENIX Association, Berkeley, CA."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1346281.1346284"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1995896.1995914"},{"key":"e_1_2_1_11_1","unstructured":"CVE-2009-1897 2009. CVE-2009-1897: NULL dereference and mmap of \/dev\/net\/tun in Linux kernel allows privilege escalation. Retrieved from http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name&equals;CVE-2009-3527.  CVE-2009-1897 2009. CVE-2009-1897: NULL dereference and mmap of \/dev\/net\/tun in Linux kernel allows privilege escalation. Retrieved from http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name&equals;CVE-2009-3527."},{"key":"e_1_2_1_12_1","unstructured":"CVE-2009-3527 2009. CVE-2009-3527: Race condition in Pipe (IPC) close in FreeBSD allows privilege escalation. (2009). Available online: http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name&equals;CVE-2009-1897.  CVE-2009-3527 2009. CVE-2009-3527: Race condition in Pipe (IPC) close in FreeBSD allows privilege escalation. (2009). Available online: http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name&equals;CVE-2009-1897."},{"key":"e_1_2_1_13_1","unstructured":"CVE-2010-4258 2010. CVE-2010-4258: do_exit does not properly handle a KERNEL_DS value allowing privilege escalation. Retrieved from http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name&equals;CVE-2010-4258.  CVE-2010-4258 2010. CVE-2010-4258: do_exit does not properly handle a KERNEL_DS value allowing privilege escalation. Retrieved from http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name&equals;CVE-2010-4258."},{"key":"e_1_2_1_14_1","unstructured":"CVE-2012-5513 2012. CVE-2012-5513: XENMEM_exchange handler does not properly check the memory address allowing privilege escalation. Retrieved from http:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId&equals;CVE-2012-5513.  CVE-2012-5513 2012. CVE-2012-5513: XENMEM_exchange handler does not properly check the memory address allowing privilege escalation. Retrieved from http:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId&equals;CVE-2012-5513."},{"key":"e_1_2_1_15_1","unstructured":"CVE Details 2015. CVE Details: The ultimate security vulnerability datasource. Retrieved from http:\/\/www.cvedetails.com\/.  CVE Details 2015. CVE Details: The ultimate security vulnerability datasource. Retrieved from http:\/\/www.cvedetails.com\/."},{"key":"e_1_2_1_16_1","unstructured":"R. de C Valle. 2009. Linux sock_sendpage() NULL pointer dereference. Retrieved from http:\/\/packetstormsecurity.com\/files\/81212\/Linux-sock_sendpage-NULL-Po inter-Dereference.html.  R. de C Valle. 2009. Linux sock_sendpage() NULL pointer dereference. Retrieved from http:\/\/packetstormsecurity.com\/files\/81212\/Linux-sock_sendpage-NULL-Po inter-Dereference.html."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2086696.2086714"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315294"},{"key":"e_1_2_1_20_1","unstructured":"edb1 2009. EDB-9477: sock_sendpage() local root exploit in Linux. (2009). Available online: http:\/\/www.exploit-db.com\/exploits\/9477\/.  edb1 2009. EDB-9477: sock_sendpage() local root exploit in Linux. (2009). Available online: http:\/\/www.exploit-db.com\/exploits\/9477\/."},{"volume-title":"EDB-17391: DEC Alpha Linux &lt;&equals","year":"2011","key":"e_1_2_1_21_1","unstructured":"edb2 2011. EDB-17391: DEC Alpha Linux &lt;&equals ; 3.0 local root exploit. ( 2011 ). Available online: http:\/\/www.exploit-db.com\/exploits\/17391\/. edb2 2011. EDB-17391: DEC Alpha Linux &lt;&equals; 3.0 local root exploit. (2011). Available online: http:\/\/www.exploit-db.com\/exploits\/17391\/."},{"volume-title":"Proceedings of the International Symposium on High Performamce Computer Architecture (HPCA\u201914)","author":"Elwell J.","key":"e_1_2_1_22_1","unstructured":"J. Elwell , R. Riley , N. Abu-Ghazaleh , and D. Ponomarev . 2014. A non-inclusive memory permissions architecture for protecting against cross-layer attacks . In Proceedings of the International Symposium on High Performamce Computer Architecture (HPCA\u201914) . J. Elwell, R. Riley, N. Abu-Ghazaleh, and D. Ponomarev. 2014. A non-inclusive memory permissions architecture for protecting against cross-layer attacks. In Proceedings of the International Symposium on High Performamce Computer Architecture (HPCA\u201914)."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2014.25"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/361011.361070"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPADS.2010.44"},{"volume-title":"Proceedings of the Network and Distributed Systems Security Symposium. 191--206","author":"Garfinkel T.","key":"e_1_2_1_26_1","unstructured":"T. Garfinkel and M. Rosenblum . 2003. A virtual machine introspection based architecture for intrusion detection . In Proceedings of the Network and Distributed Systems Security Symposium. 191--206 . T. Garfinkel and M. Rosenblum. 2003. A virtual machine introspection based architecture for intrusion detection. In Proceedings of the Network and Distributed Systems Security Symposium. 191--206."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/2487726.2488370"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2451116.2451146"},{"key":"e_1_2_1_29_1","unstructured":"Intel. 2014. Intel 64 and IA32 architectures software developer\u2019s manual. (2014). Retrieved from http:\/\/www.intel.com\/content\/dam\/www\/public\/us\/en\/documents\/manuals\/64-ia-32-architectures-software-developer-manual-325462.pdf.  Intel. 2014. Intel 64 and IA32 architectures software developer\u2019s manual. (2014). Retrieved from http:\/\/www.intel.com\/content\/dam\/www\/public\/us\/en\/documents\/manuals\/64-ia-32-architectures-software-developer-manual-325462.pdf."},{"key":"e_1_2_1_30_1","doi-asserted-by":"crossref","unstructured":"X. Jiang and X. Wang. 2007. Out-of-the-box monitoring of VM-based high-interaction honeypots. In Recent Advances in Intrusion Detection (RAID\u201907). 198--218.   X. Jiang and X. Wang. 2007. Out-of-the-box monitoring of VM-based high-interaction honeypots. In Recent Advances in Intrusion Detection (RAID\u201907). 198--218.","DOI":"10.1007\/978-3-540-74320-0_11"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315262"},{"volume-title":"Proceedings of the 21st USENIX Conference on Security Symposium. USENIX Association, 39--39","author":"Kemerlis V. P.","key":"e_1_2_1_32_1","unstructured":"V. P. Kemerlis , G. Portokalidis , and A. D. Keromytis . 2012. kGuard: Lightweight kernel protection against return-to-user attacks . In Proceedings of the 21st USENIX Conference on Security Symposium. USENIX Association, 39--39 . V. P. Kemerlis, G. Portokalidis, and A. D. Keromytis. 2012. kGuard: Lightweight kernel protection against return-to-user attacks. In Proceedings of the 21st USENIX Conference on Security Symposium. USENIX Association, 39--39."},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1629575.1629596"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2005.14"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/378993.379237"},{"volume-title":"Proceedings of the 17th Usenix Security Symposium.","author":"Litty L.","key":"e_1_2_1_36_1","unstructured":"L. Litty , H. Lagar-Cavilla , and D. Lie . 2008. Hypervisor support for identifying covertly executing binaries . In Proceedings of the 17th Usenix Security Symposium. L. Litty, H. Lagar-Cavilla, and D. Lie. 2008. Hypervisor support for identifying covertly executing binaries. In Proceedings of the 17th Usenix Security Symposium."},{"key":"e_1_2_1_37_1","unstructured":"MARSS. 2013. MARSSx86: Micro-ARchitectural and System Simulator for x86-based systems. Retrieved from http:\/\/marss86.org. Simulator source code and documentation.  MARSS. 2013. MARSSx86: Micro-ARchitectural and System Simulator for x86-based systems. Retrieved from http:\/\/marss86.org. Simulator source code and documentation."},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/2487726.2488368"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516678"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.11"},{"volume-title":"Proceedings of the Annual Computer Security Applications Conference.","author":"Payne B.","key":"e_1_2_1_41_1","unstructured":"B. Payne , M. Carbone , and W. Lee . 2007. Secure and flexible monitoring of virtual machines . In Proceedings of the Annual Computer Security Applications Conference. B. Payne, M. Carbone, and W. Lee. 2007. Secure and flexible monitoring of virtual machines. In Proceedings of the Annual Computer Security Applications Conference."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.24"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.5555\/1433006.1433008"},{"key":"e_1_2_1_44_1","volume-title":"Proceedings of the 13th Usenix Security Symposium.","author":"Sailer R.","year":"2004","unstructured":"R. Sailer , X. Zhang , T. Jaeger , and L. van Doorn . 2004 . Design and implementation of a TCG-based integrity measurement architecture . In Proceedings of the 13th Usenix Security Symposium. R. Sailer, X. Zhang, T. Jaeger, and L. van Doorn. 2004. Design and implementation of a TCG-based integrity measurement architecture. In Proceedings of the 13th Usenix Security Symposium."},{"key":"e_1_2_1_45_1","unstructured":"Security Focus. 2009. BID-36939: Microsoft windows kernel NULL pointer dereference local privilege escalation vulnerability. (2009). Available online: http:\/\/www.securityfocus.com\/bid\/36939.  Security Focus. 2009. BID-36939: Microsoft windows kernel NULL pointer dereference local privilege escalation vulnerability. (2009). Available online: http:\/\/www.securityfocus.com\/bid\/36939."},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/1294261.1294294"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653720"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/2155620.2155652"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/782814.782838"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046754"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/2150976.2151022"},{"key":"e_1_2_1_52_1","unstructured":"TPM. 2013. TPM main specification. Retrieved from http:\/\/www.trustedcomputinggroup.org\/resources\/tpm_main_specification.  TPM. 2013. TPM main specification. Retrieved from http:\/\/www.trustedcomputinggroup.org\/resources\/tpm_main_specification."},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/1250662.1250723"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2008.4771781"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/605397.605429"},{"volume-title":"Proceeding of the 41st Annual International Symposium on Computer Architecuture. IEEE Press, 457--468","author":"Woodruff J.","key":"e_1_2_1_56_1","unstructured":"J. Woodruff , R. N. M. Watson , D. Chisnall , S. W. Moore , J. Anderson , B. Davis , B. Laurie , P. G. Neumann , R. Norton , and M. Roe . 2014. The CHERI capability model: Revisiting RISC in an age of risk . In Proceeding of the 41st Annual International Symposium on Computer Architecuture. IEEE Press, 457--468 . J. Woodruff, R. N. M. Watson, D. Chisnall, S. W. Moore, J. Anderson, B. Davis, B. Laurie, P. G. Neumann, R. Norton, and M. Roe. 2014. The CHERI capability model: Revisiting RISC in an age of risk. In Proceeding of the 41st Annual International Symposium on Computer Architecuture. IEEE Press, 457--468."},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2013.6522323"},{"key":"e_1_2_1_58_1","unstructured":"Xilinx. 2013. Xilinx 7 Series FPGAs overview. Retrieved from http:\/\/www.xilinx.com\/support\/documentation\/data_sheets\/ds180_7Series_O verview.pdf.  Xilinx. 2013. Xilinx 7 Series FPGAs overview. Retrieved from http:\/\/www.xilinx.com\/support\/documentation\/data_sheets\/ds180_7Series_O verview.pdf."},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/2043556.2043576"}],"container-title":["ACM Transactions on Architecture and Code Optimization"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2842621","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2842621","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:53:48Z","timestamp":1750222428000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2842621"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,12,8]]},"references-count":58,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2016,1,7]]}},"alternative-id":["10.1145\/2842621"],"URL":"https:\/\/doi.org\/10.1145\/2842621","relation":{},"ISSN":["1544-3566","1544-3973"],"issn-type":[{"type":"print","value":"1544-3566"},{"type":"electronic","value":"1544-3973"}],"subject":[],"published":{"date-parts":[[2015,12,8]]},"assertion":[{"value":"2014-04-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2015-11-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2015-12-08","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}