RAM LABORATORIES — Department of Defense SBIR Phase I: N172-105
RAM LABORATORIES — SBIR Phase I award from Department of Defense.
- Amount
- $124,998
- Agency
- Department of Defense · Navy
- Program / Phase
- SBIR · Phase I
- Topic
- N172-105
- Solicitation
- 2017.2
- NAICS
- —
- Place of performance
- CA
- Period
- 2017-11-30 → 2018-10-01
Description
One of the largest threats to multi-level secure operating systems are zero-day privilege escalation attacks that allow an adversary to gain root privileges and break out of any sandbox environment. To combat these challenges RAM Laboratories is proposing a secure dual-classification operating system with kernel integrity modules that prevent this style of attacks. First, instead of simultaneously running two classification levels in virtual environments, we have two versions of the operating system installed on the device, each encrypted with separate keys. This means that an adversary, at any privilege level, will be unable to gain access to the other classification level, as the proper key would be needed to decrypt and access the other classification level. However, even if an adversary cannot access the other classification level, we still want to prevent them from gaining root privileges at all. To this end, we use the ARM TrustZone to enforce kernel integrity, with modules executing in a Trusted Execution Environment (TEE) offering a much smaller Trusted Computing Base (TCB) than typical hypervisors or full-fledged kernels. By enforcing a few security properties, the modules are able to prevent any adversary from executing user-space code with kernel privileges, preventing any privilege escalation attack.