Varan the unbelievable: an efficient n-version execution framework
File(s)varan-asplos-14.pdf (862.12 KB)
Accepted version
Author(s)
Hosek, P
Cadar, C
Type
Conference Paper
Abstract
With the widespread availability of multi-core processors, running multiple diversified variants or several different versions of an application in parallel is becoming a viable approach for increasing the reliability and security of software systems. The key component of such N-version execution (NVX) systems is a runtime monitor that enables the execution of multiple versions in parallel. Unfortunately, existing monitors impose either a large performance overhead or rely on intrusive kernel-level changes.
Moreover, none of the existing solutions scales well with the number of versions, since the runtime monitor acts as a performance bottleneck. In this paper, we introduce VARAN, an NVX framework that combines selective binary rewriting with a novel event streaming architecture to significantly reduce performance overhead and scale well with the number of versions, without relying on intrusive kernel modifications. Our evaluation shows that VARAN can run NVX systems based on popular C10k network servers with only a modest performance overhead, and can be effectively used to increase software reliability using techniques such as transparent failover, live sanitization and multi-revision execution.
Moreover, none of the existing solutions scales well with the number of versions, since the runtime monitor acts as a performance bottleneck. In this paper, we introduce VARAN, an NVX framework that combines selective binary rewriting with a novel event streaming architecture to significantly reduce performance overhead and scale well with the number of versions, without relying on intrusive kernel modifications. Our evaluation shows that VARAN can run NVX systems based on popular C10k network servers with only a modest performance overhead, and can be effectively used to increase software reliability using techniques such as transparent failover, live sanitization and multi-revision execution.
Date Issued
2015-03-14
Date Acceptance
2015-03-01
Citation
ASPLOS '15: Proceedings of the Twentieth International Conference on Architectural Support for Programming Languages and Operating Systems, 2015, 50 (4), pp.339-353
ISBN
978-1-4503-2835-7
ISSN
0362-1340
Publisher
ACM Digital Library
Start Page
339
End Page
353
Journal / Book Title
ASPLOS '15: Proceedings of the Twentieth International Conference on Architectural Support for Programming Languages and Operating Systems
Volume
50
Issue
4
Copyright Statement
Copyright © is held by the owner/author(s). Publication rights licensed to ACM. This is the author's version of the work. It is posted here by permission of ACM for your personal use. Not for redistribution. The definitive version was published in ASPLOS '15, (2015) http://doi.acm.org/10.1145/2694344.2694390
Sponsor
Engineering & Physical Science Research Council (EPSRC)
Identifier
http://srg.doc.ic.ac.uk/files/papers/varan-asplos-14.pdf
Grant Number
EP/L002795/1
Source
International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS 2015)
Subjects
Science & Technology
Technology
Computer Science, Software Engineering
Computer Science
Reliability
Performance
N-version execution
selective binary rewriting
event streaming
transparent failover
multi-revision execution
live sanitization
record-replay
Software Engineering
Publication Status
Published
Start Date
2015-03-14
Finish Date
2015-03-18
Coverage Spatial
New York, USA
Date Publish Online
2015-03