STrace – A DTrace on Windows Reimplementation
twitter.com
twitter.com
This work was presented at DEFCON 30 this week. Happy to answer any questions!
Aren’t “embedding web assembly into the kernel” and “mapping DLLs into the kernel” too dangerous to call this a dtrace reimplementation?
For dlls in the kernel, yes absolutely insecure. It's intended to be a tool run in an analysis VM not on endpoint user systems. The security model is simply different for the DLL based architecture. One of the big reasons I am ok with this design is because driver signature enforcement already must be manually disabled to load the C driver that uses DLLs like this. With DSE off you can already easily load unsigned kernel code so this doesn't open any additional security holes.
it's a dtrace reimplementation because it's using those kernel interfaces. The architecture of the scripting system on top of that could be anything. The wasm rust system mirrors MS' architecture, the C++ DLL system differs intentionally from it.
“To prevent DIF from inducing an infinite loop in probe context, only forward branches are permitted. This safety provision may seem draconian — it eliminates loops altogether — but in practice we have not discovered it to present a serious limitation”
And we disagree about what can be called “a dtrace reimplementation”. Because there’s decades of prior art on tracing, I wouldn’t call anything that allows looping that.