Login

A Machine-Checked Safety Proof for a CISC-Compatible SFI Technique

Show full item record




Title: A Machine-Checked Safety Proof for a CISC-Compatible SFI Technique
Author: McCamant, Stephen
Other Contributors: Program Analysis
Advisor: Michael Ernst
Issue Date: 2006-05-11
Abstract: Executing untrusted code while preserving security requires that thecode be prevented from modifying memory or executing instructionsexcept as explicitly allowed. Software-based fault isolation (SFI) or"sandboxing" enforces such a policy by rewriting code at theinstruction level. In previous work, we developed a new SFI techniquethat is applicable to CISC architectures such as the Intel IA-32,based on enforcing additional alignment constraints to avoiddifficulties with variable-length instructions. This report describesa machine-checked proof we developed to increase our confidence in thesafety provided by the technique. The proof, constructed for asimplified model of the technique using the ACL2 theorem provingenvironment, certifies that if the code rewriting has been checked tohave been performed correctly, the resulting program cannot perform adangerous operation when run. We describe the high-level structure ofthe proof, then give the intermediate lemmas with interspersedcommentary, and finally evaluate the process of the proof'sconstruction.
URI: http://hdl.handle.net/1721.1/32546
Other Identifiers: MIT-CSAIL-TR-2006-035
Series/Report no.: Massachusetts Institute of Technology Computer Science and Artificial Intelligence Laboratory

Files in this item

Files Size Format View
MIT-CSAIL-TR-2006-035.pdf 499.3Kb PDF View/Open

Files in this item

Files Size Format View
MIT-CSAIL-TR-2006-035.ps 1.456Mb Postscript View/Open

This item appears in the following Collection(s)

Show full item record

Search DSpace@MIT


Advanced Search

Browse

My Account

Links