{"id":13641628,"url":"https://github.com/cloud-security-research/sgx-ids","last_synced_at":"2025-04-20T11:31:35.663Z","repository":{"id":192001273,"uuid":"120658045","full_name":"cloud-security-research/sgx-ids","owner":"cloud-security-research","description":null,"archived":true,"fork":false,"pushed_at":"2022-12-20T16:14:46.000Z","size":4797,"stargazers_count":13,"open_issues_count":1,"forks_count":4,"subscribers_count":4,"default_branch":"master","last_synced_at":"2024-08-03T01:24:06.419Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Lua","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/cloud-security-research.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2018-02-07T19:00:30.000Z","updated_at":"2023-06-21T15:14:34.000Z","dependencies_parsed_at":"2023-09-02T00:13:37.721Z","dependency_job_id":null,"html_url":"https://github.com/cloud-security-research/sgx-ids","commit_stats":null,"previous_names":["cloud-security-research/sgx-ids"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloud-security-research%2Fsgx-ids","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloud-security-research%2Fsgx-ids/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloud-security-research%2Fsgx-ids/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloud-security-research%2Fsgx-ids/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/cloud-security-research","download_url":"https://codeload.github.com/cloud-security-research/sgx-ids/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":223827489,"owners_count":17209796,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-02T01:01:22.435Z","updated_at":"2024-11-09T12:30:37.493Z","avatar_url":"https://github.com/cloud-security-research.png","language":"Lua","funding_links":[],"categories":["Network"],"sub_categories":["Library OSes and SDKs"],"readme":"# Snort Intrusion Detection System with Intel Software Guard Extension (Intel SGX)\n\n\u003e :warning: **DISCONTINUATION OF PROJECT** - *This project will no longer be maintained by Intel.  Intel has ceased development and contributions including, but not limited to, maintenance, bug fixes, new releases, or updates, to this project.* **Intel no longer accepts patches to this project.**\n\n\nThis software is a research proof of concept and not intended for production use\n\nNetwork Function Virtualization (NFV) promises the benefits of reduced infrastructure, personnel, and management costs by outsourcing network middleboxes to the public or private cloud. Unfortunately, running network functions in the cloud entails security challenges, especially for complex stateful services. , SEC-IDS is an research attempt to harden the king of middleboxes - Intrusion Detection Systems (IDS) - using Intel Software Guard Extensions (Intel SGX) technology. SEC-IDS, is an unmodified Snort 3 with a DPDK network layer that achieves line rate throughput. SEC-IDS achieves computational integrity by running all Snort code inside an Intel SGX enclave. At the same time, SEC-IDS achieves near-native performance, with throughput close to 100 percent of vanilla Snort 3, by retaining network I/O outside of the enclave. Our experiments indicate that performance is only constrained by the limited amount of  Enclave physical memory available on current Intel SGX Skylake based E3 Xeon platforms. Finally, we kept the porting effort minimal by using the Graphene-SGX library OS. Only 27 Lines of Code (LoC) were modified in Snort and 178 LoC in Graphene-SGX itself.\n\n\n## How to run build and run SEC-IDS\n\tprerequsites : Intel SGX Enabled server platform with a DPDK compatible 10Gbps network controller\n\n### Prepare the system first\n\nInstall Ubuntu 16.04 x86_64 on a SGX Enabled machine. Ensure Hyperthreading and Power state management is disabled in BIOS\n\n\nInstall dependencies and set appropriate kernel parameters for best performance\n\n```\n\tsudo apt update \u0026\u0026 sudo apt upgrade\n\tsudo apt install make gcc build-essential ocaml automake autoconf libtool wget python libssl-dev libcurl4-openssl-dev protobuf-compiler libprotobuf-dev libnuma-dev  python-protobuf python-crypto flex bison libpcap-dev unzip cmake hwloc libhwloc-dev pkg-config\n\tsudo apt install htop linux-tools-common linux-tools-`uname -r`\n\tsudo systemctl enable ssh  # to persist ssh daemon across reboots\n\tsudo vim /etc/default/grub # change GRUB_CMDLINE_LINUX to GRUB_CMDLINE_LINUX=\"default_hugepagesz=1GB hugepagesz=1G hugepages=16 iommu=pt intel_iommu=on intel_idle.max_cstate=0 intel_pstate=disable\"\nsudo update-grub\n\n```\n\nAdd the following line in /etc/security/limits.conf to permanently change available locked memory\n\n```\n\t*                hard    memlock         20971520\" and \"*                soft    memlock         20971520\"\n```\n\nReboot the machine!\n\nOnce the machine comes up execute the following commands. Note: These commands need to be executed on every boot\n\n```\n\tmkdir /mnt/huge\n\tmount -t hugetlbfs nodev /mnt/huge\n\tulimit -l unlimited  # in case limits.conf doesn't help\n\tsudo sysctl vm.mmap_min_addr=0\n```\n\nOptionally, to set the correct date/time on the system, execute the following command\n\n```\n\tsudo date -s \"$(wget -qSO- --max-redirect=0 google.com 2\u003e\u00261 | grep Date: | cut -d' ' -f5-8)Z\"  # for correct datetime\n```\n\n\nThe build.sh script will automatically build and configure all necessary components automatically. \nMake changes in the script as required. The complete build process may take upto 15 minutes\n\nNOTE: provide the absolute path of linux sgx driver when prompted. That would be absolute path of ./linux-sgx-driver\n\n```\n\t./build.sh\n```\n\nNOTE !!! The following steps below the line are for reference only. The ./build.sh script will perform all steps below\n\n------------------------------------------------------------------------------------------------------------------------------\n\nInstall linux-sgx-driver\n\n```\n\tmkdir ~/01org \u0026\u0026 cd ~/01org\n\tgit clone https://github.com/01org/linux-sgx-driver \u0026\u0026 cd linux-sgx-driver\n\tmake\n\tsudo mkdir -p \"/lib/modules/\"`uname -r`\"/kernel/drivers/intel/sgx\"          # the following commands are from linux-sgx-driver README\n\tsudo cp isgx.ko \"/lib/modules/\"`uname -r`\"/kernel/drivers/intel/sgx\"\n\tsudo sh -c \"cat /etc/modules | grep -Fxq isgx || echo isgx \u003e\u003e /etc/modules\"\n\tsudo /sbin/depmod\n\tsudo /sbin/modprobe isgx\n```\n\n\nInstall Linux SGX SDK\n\n```\n\tgit clone https://github.com/01org/linux-sgx.git \u0026\u0026 cd linux-sgx\n\t./download_prebuilt.sh   # the following commands are from linux-sgx README\n\tmake\n\tmake sdk_install_pkg\n\tmake psw_install_pkg\n\tcd linux/installer/bin \u0026\u0026 sudo ./sgx_linux_x64_psw_${version}.bin \n\tcd linux/installer/bin \u0026\u0026 sudo ./sgx_linux_x64_sdk_${version}.bin  # Choose \"/opt/intel\" as installdir \n\tsudo service aesmd start\n\tcd /opt/intel/sgxsdk/SampleCode/LocalAttestation \u0026\u0026 make \u0026\u0026  ./app  # simple test that SGX SDK works\n```\n\n\n\nInstall Intel DPDK  (SGX-Snort was tested with DPDK 17.08)\n\n```\n\tcd ~\n\tgit clone http://dpdk.org/git/dpdk \u0026\u0026 cd dpdk\n\tmake install T=x86_64-native-linuxapp-gcc DESTDIR=install  EXTRA_CFLAGS=\"-fPIC\"\n\techo 'export RTE_SDK=$HOME/dpdk' \u003e\u003e ~/.bashrc\n\techo 'export RTE_TARGET=x86_64-native-linuxapp-gcc' \u003e\u003e ~/.bashrc\n\tcd usertools \u0026\u0026 sudo ./dpdk-setup.sh  # choose \"[17] Insert VFIO module\"; then \"[23] Bind Ethernet/Crypto device to VFIO module\" for all required network interfaces; then \"[24] Setup VFIO permissions\"\n```\n\nApply graphene patches and Build Graphene-SGX. Also build libdaq libraries to link with Graphene PAL\n\n```\n    git clone --recursive https://github.com/oscarlab/graphene.git\n    pushd graphene\n    git reset --hard 4d8eacdd44029af28887247ebeb11b3d3ac1f6df\n    patch -p1 \u003c ../misc/graphene-pull-request-58.patch || exit 1\n    pushd Pal/src/host/Linux-SGX/sgx-driver/\n    make\n    ./load.sh\n    popd\n    patch -p2 \u003c ../misc/graphene-01-mmap-map32bit.diff || exit 1\n    patch -p2 \u003c ../misc/graphene-02-unmap-tcs.diff || exit 1\n    patch -p2 \u003c ../misc/graphene-03-trustedclock-dpdkocalls.diff || exit 1\n    sed -i -r 's/CPUFREQ [0-9]+\\.[0-9]+/CPUFREQ 3785.0/' Pal/src/host/Linux-SGX/enclave_ocalls.c # Adjust CPUFREQ here based on CPU frequency\n    openssl genrsa -3 -out Pal/src/host/Linux-SGX/signer/enclave-key.pem 3072\n    export RTE_SDK=$(readlink -f ../dpdk)\n    export RTE_TARGET=x86_64-native-linuxapp-gcc\n    cp -a ../apps/* LibOS/shim/test/apps/\n    make -C LibOS/shim/test/apps/libdaq -f Makefile.untrusted\n    make clean \u0026\u0026 make SGX=1\n```\n\nThen build snort and depdendent libaries with graphene SGX support\n\n```\n    make -C LibOS/shim/test/apps\n\n```\n\n--------------------------------------------------------------------------------------------------------------------------\n\n\n### Time to test SGX snort ...Success if you see snort version output\n\n```\n\texport LD_LIBRARY_PATH=\"$LD_LIBRARY_PATH\":$(readlink -f graphene/LibOS/shim/test/apps/libdaq/install/lib)\n\tcd graphene/LibOS/shim/test/apps/snort3 \u0026\u0026 SGX=1 ./pal_loader snort3.manifest.sgx --version \u0026\u0026 cd -\n\n```\n\nTest helloworld app inside Graphene-SGX to make sure the installation was successful\n\n```\n\tcd graphene/LibOS/shim/test/native/ \u0026\u0026 make SGX=1 DEBUG=1 \u0026\u0026 make SGX_RUN=1 \u0026\u0026 ./pal_loader SGX helloworld\n```\n\nRun experiments on SGX-Snort (NOTE: change constants in run scripts for your configuration beforehand!)\n\n```\n\t./graphene-snort/LibOS/shim/test/apps/snort3 \u0026\u0026 run.sh -v=sgx\n```\n\nRun experiments on vanilla Snort (NOTE: change constants in run scripts for your configuration beforehand!)\n\n```\n\t./graphene-snort/LibOS/shim/test/apps/snort3 \u0026\u0026 run.sh -v=vanilla\n```\n\n\nSample rules are already present in ~/code/graphene-snort/LibOS/shim/test/apps/snort3/rules/ folder. \nyou can also add rules by adding the new rules file in the folder. \n\nLatest Rules are available at https://www.snort.org/downloads/community/snort3-community-rules.tar.gz\n\nTo use new rules in SEC-IDS you must add the new rules file name in the snort manifest file\n\n```\n\t./graphene/LibOS/shim/test/apps/snort3/snort3.manifest.template:sgx.allowed_files.rules6 = file:install/etc/snort/\u003cnew_rules_file\u003e.rules\n```\n\nInclude the new rule file in snortrules for snort to use it\n\n```\n\t./graphene/LibOS/shim/test/apps/snort3/run.sh:declare -a   snortrules=(\"\" \"\" \"\u003cnew_rules_file\u003e.rules\")\n```\n\n\n### LICENSE INFORMATION\n\nSnort v3 and daq-2.2.1 patches are released under GPLv2\n\nGraphene patches are released under LGPL\n\nBuild and run scripts are released under Apache 2.0\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcloud-security-research%2Fsgx-ids","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcloud-security-research%2Fsgx-ids","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcloud-security-research%2Fsgx-ids/lists"}