Passer à la navigation principale Passer à la recherche Passer au contenu principal

seL4: From general purpose to a proof of information flow enforcement

  • Toby Murray
  • , Daniel Matichuk
  • , Matthew Brassil
  • , Peter Gammie
  • , Timothy Bourke
  • , Sean Seefried
  • , Corey Lewis
  • , Xin Gao
  • , Gerwin Klein
  • Commonwealth Scientific and Industrial Research Organization
  • University of New South Wales

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

175 Citations (Scopus)

Résumé

In contrast to testing, mathematical reasoning and formal verification can show the absence of whole classes of security vulnerabilities. We present the, to our knowledge, first complete, formal, machine-checked verification of information flow security for the implementation of a general-purpose microkernel; namely seL4. Unlike previous proofs of information flow security for operating system kernels, ours applies to the actual 8, 830 lines of C code that implement seL4, and so rules out the possibility of invalidation by implementation errors in this code. We assume correctness of compiler, assembly code, hardware, and boot code. We prove everything else. This proof is strong evidence of seL4's utility as a separation kernel, and describes precisely how the general purpose kernel should be configured to enforce isolation and mandatory information flow control. We describe the information flow security statement we proved (a variant of intransitive noninterference), including the assumptions on which it rests, as well as the modifications that had to be made to seL4 to ensure it was enforced. We discuss the practical limitations and implications of this result, including covert channels not covered by the formal proof.

langue originaleAnglais
titreProceedings - 2013 IEEE Symposium on Security and Privacy, SP 2013
Pages415-429
Nombre de pages15
Les DOIs
étatPublié - 13 août 2013
Modification externeOui
Evénement34th IEEE Symposium on Security and Privacy, SP 2013 - San Francisco, CA, États-Unis
Durée: 19 mai 201322 mai 2013

Série de publications

NomProceedings - IEEE Symposium on Security and Privacy
ISSN (imprimé)1081-6011

Une conférence

Une conférence34th IEEE Symposium on Security and Privacy, SP 2013
Pays/TerritoireÉtats-Unis
La villeSan Francisco, CA
période19/05/1322/05/13

Empreinte digitale

Examiner les sujets de recherche de « seL4: From general purpose to a proof of information flow enforcement ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation