|国家预印本平台
首页|Enabling Security on the Edge: A CHERI Compartmentalized Network Stack

Enabling Security on the Edge: A CHERI Compartmentalized Network Stack

Enabling Security on the Edge: A CHERI Compartmentalized Network Stack

来源:Arxiv_logoArxiv
英文摘要

The widespread deployment of embedded systems in critical infrastructures, interconnected edge devices like autonomous drones, and smart industrial systems requires robust security measures. Compromised systems increase the risks of operational failures, data breaches, and -- in safety-critical environments -- potential physical harm to people. Despite these risks, current security measures are often insufficient to fully address the attack surfaces of embedded devices. CHERI provides strong security from the hardware level by enabling fine-grained compartmentalization and memory protection, which can reduce the attack surface and improve the reliability of such devices. In this work, we explore the potential of CHERI to compartmentalize one of the most critical and targeted components of interconnected systems: their network stack. Our case study examines the trade-offs of isolating applications, TCP/IP libraries, and network drivers on a CheriBSD system deployed on the Arm Morello platform. Our results suggest that CHERI has the potential to enhance security while maintaining performance in embedded-like environments.

Donato Ferraro、Andrea Bastoni、Alexander Zuepke、Andrea Marongiu

安全科学

Donato Ferraro,Andrea Bastoni,Alexander Zuepke,Andrea Marongiu.Enabling Security on the Edge: A CHERI Compartmentalized Network Stack[EB/OL].(2025-07-07)[2025-07-21].https://arxiv.org/abs/2507.04818.点此复制

评论