{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:WB7URRWKINXJKGSJKCAZICE7BB","short_pith_number":"pith:WB7URRWK","schema_version":"1.0","canonical_sha256":"b07f48c6ca436e951a49508194089f084437acb9b4dc3d08f5c333ac38a09ecf","source":{"kind":"arxiv","id":"2409.09606","version":1},"attestation_state":"computed","paper":{"title":"BULKHEAD: Secure, Scalable, and Efficient Kernel Compartmentalization with PKS","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.OS"],"primary_cat":"cs.CR","authors_text":"Kangjie Lu, Qingkai Zeng, Weiheng Bai, Yinggang Guo, Zicheng Wang","submitted_at":"2024-09-15T04:11:26Z","abstract_excerpt":"The endless stream of vulnerabilities urgently calls for principled mitigation to confine the effect of exploitation. However, the monolithic architecture of commodity OS kernels, like the Linux kernel, allows an attacker to compromise the entire system by exploiting a vulnerability in any kernel component. Kernel compartmentalization is a promising approach that follows the least-privilege principle. However, existing mechanisms struggle with the trade-off on security, scalability, and performance, given the challenges stemming from mutual untrustworthiness among numerous and complex componen"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2409.09606","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-09-15T04:11:26Z","cross_cats_sorted":["cs.OS"],"title_canon_sha256":"9dc460f556b92348b384b32913f655458b122bd46d0f1bb4d7ef641f14711e0b","abstract_canon_sha256":"1620ac0a1ec9fa225ba4c0b6db6574231161673ed981c58ca2e0d028235118e8"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:07:11.963745Z","signature_b64":"X3qh97X0l2bohcBfzMeI2Kn3bJzQ4LBhGSHoj5XU9Xi2RLEmSUIZ1Rd+Wsuidiah50ICEID0qPpyPEaT0kddCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b07f48c6ca436e951a49508194089f084437acb9b4dc3d08f5c333ac38a09ecf","last_reissued_at":"2026-07-05T09:07:11.963355Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:07:11.963355Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"BULKHEAD: Secure, Scalable, and Efficient Kernel Compartmentalization with PKS","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.OS"],"primary_cat":"cs.CR","authors_text":"Kangjie Lu, Qingkai Zeng, Weiheng Bai, Yinggang Guo, Zicheng Wang","submitted_at":"2024-09-15T04:11:26Z","abstract_excerpt":"The endless stream of vulnerabilities urgently calls for principled mitigation to confine the effect of exploitation. However, the monolithic architecture of commodity OS kernels, like the Linux kernel, allows an attacker to compromise the entire system by exploiting a vulnerability in any kernel component. Kernel compartmentalization is a promising approach that follows the least-privilege principle. However, existing mechanisms struggle with the trade-off on security, scalability, and performance, given the challenges stemming from mutual untrustworthiness among numerous and complex componen"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2409.09606","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2409.09606/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2409.09606","created_at":"2026-07-05T09:07:11.963411+00:00"},{"alias_kind":"arxiv_version","alias_value":"2409.09606v1","created_at":"2026-07-05T09:07:11.963411+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2409.09606","created_at":"2026-07-05T09:07:11.963411+00:00"},{"alias_kind":"pith_short_12","alias_value":"WB7URRWKINXJ","created_at":"2026-07-05T09:07:11.963411+00:00"},{"alias_kind":"pith_short_16","alias_value":"WB7URRWKINXJKGSJ","created_at":"2026-07-05T09:07:11.963411+00:00"},{"alias_kind":"pith_short_8","alias_value":"WB7URRWK","created_at":"2026-07-05T09:07:11.963411+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.20906","citing_title":"ParaCell: Paravirtualized Secure Containers with Lightweight Intra-Container Isolation and Intent-Driven Memory Management","ref_index":36,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/WB7URRWKINXJKGSJKCAZICE7BB","json":"https://pith.science/pith/WB7URRWKINXJKGSJKCAZICE7BB.json","graph_json":"https://pith.science/api/pith-number/WB7URRWKINXJKGSJKCAZICE7BB/graph.json","events_json":"https://pith.science/api/pith-number/WB7URRWKINXJKGSJKCAZICE7BB/events.json","paper":"https://pith.science/paper/WB7URRWK"},"agent_actions":{"view_html":"https://pith.science/pith/WB7URRWKINXJKGSJKCAZICE7BB","download_json":"https://pith.science/pith/WB7URRWKINXJKGSJKCAZICE7BB.json","view_paper":"https://pith.science/paper/WB7URRWK","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2409.09606&json=true","fetch_graph":"https://pith.science/api/pith-number/WB7URRWKINXJKGSJKCAZICE7BB/graph.json","fetch_events":"https://pith.science/api/pith-number/WB7URRWKINXJKGSJKCAZICE7BB/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/WB7URRWKINXJKGSJKCAZICE7BB/action/timestamp_anchor","attest_storage":"https://pith.science/pith/WB7URRWKINXJKGSJKCAZICE7BB/action/storage_attestation","attest_author":"https://pith.science/pith/WB7URRWKINXJKGSJKCAZICE7BB/action/author_attestation","sign_citation":"https://pith.science/pith/WB7URRWKINXJKGSJKCAZICE7BB/action/citation_signature","submit_replication":"https://pith.science/pith/WB7URRWKINXJKGSJKCAZICE7BB/action/replication_record"}},"created_at":"2026-07-05T09:07:11.963411+00:00","updated_at":"2026-07-05T09:07:11.963411+00:00"}