Safe software updates via multi-version execution
File(s)DTR11-13.pdf (332.13 KB)
Published version
Author(s)
Hosek, Petr
Cadar, Cristian
Type
Report
Abstract
Software systems are constantly evolving, with
new versions and patches being released on a continuous basis.
Unfortunately, software updates present a high risk, with many
releases introducing new bugs and security vulnerabilities.
We tackle this problem using a simple but effective multiversion
based approach. Whenever a new update becomes
available, instead of upgrading the software to the new version,
we run the new version in parallel with the old; by carefully
coordinating their executions and selecting the behavior of the
more reliable version when they diverge, we create a more
secure and dependable multi-version application.
We have implemented this technique in a prototype system
targeting multicore processors, and show that it can be applied
successfully to several security-critical applications, such as
lighttpd and redis.
new versions and patches being released on a continuous basis.
Unfortunately, software updates present a high risk, with many
releases introducing new bugs and security vulnerabilities.
We tackle this problem using a simple but effective multiversion
based approach. Whenever a new update becomes
available, instead of upgrading the software to the new version,
we run the new version in parallel with the old; by carefully
coordinating their executions and selecting the behavior of the
more reliable version when they diverge, we create a more
secure and dependable multi-version application.
We have implemented this technique in a prototype system
targeting multicore processors, and show that it can be applied
successfully to several security-critical applications, such as
lighttpd and redis.
Date Issued
2011-01-01
Citation
Departmental Technical Report: 11/13, 2011, pp.1-12
Publisher
Department of Computing, Imperial College London
Start Page
1
End Page
12
Journal / Book Title
Departmental Technical Report: 11/13
Copyright Statement
© 2011 The Author(s). This report is available open access under a CC-BY-NC-ND (https://creativecommons.org/licenses/by-nc-nd/4.0/)
Publication Status
Published
Article Number
11/13