Multimedia White Papers

XFI: Software Guards for System Address Spaces

Overview XFI is a comprehensive protection system that offers both flexible access control and fundamental integrity guarantees, at any privilege level and even for legacy code in commodity systems. For this purpose, XFI combines static analysis with inline software guards and a two-stack execution model. This paper implements XFI for Windows on the x86 architecture using binary rewriting and a simple, stand-alone verifier; the implementation's correctness depends on the verifier, but not on the rewriter. This paper has applied XFI to software such as device drivers and multimedia codecs. The resulting modules function safely within both kernel and user-mode address spaces, with only modest enforcement overheads.

Further White Paper Details
PublisherMicrosoft File FormatPDF
Date PublishedSeptember 2006
FormatWhite Papers   
Topics

Quick Sitemap Links: