Methodology for Comparing and Analyzing the Security of Interrupt-Handling Subsystems in Operating-System Kernels and Their Resilience to Interrupt Storms


Methodology for Comparing and Analyzing the Security of Interrupt-Handling Subsystems in Operating-System Kernels and Their Resilience to Interrupt Storms

Antipov Z.A. (NRU HSE, Moscow, Russia)

Abstract

This paper proposes a methodology for comparing operating systems (OSs) with respect to their resilience to interrupt storms–high-rate streams of hardware events in which interrupt handling displaces the application workload and may result in a denial-of-service (DoS) condition. The methodology combines a qualitative assessment of protection mechanisms with a quantitative computational experiment. The evaluation criteria include interrupt-source masking, interrupt coalescing (combining multiple events into a single delivery), adaptive switching to polling, management of message-signaled interrupts, interrupt affinity, kernel preemptibility, and limits on the processor time consumed by handlers. The experimental environment is based on the QEMU emulator, a virtual interrupt-generator device, and a Tiny Code Generator (TCG) plugin that performs statistical profiling of kernel and user-space execution without modifying the guest OS. The proposed approach makes it possible to relate architectural protection mechanisms to the measured reduction in the share of processor time available to the application workload.

Keywords

operating system; interrupt handling; interrupt storm; denial of service; kernel security; microkernel; QEMU; TCG plugin; statistical profiling.

Edition

Proceedings of the Institute for System Programming, vol. 38, issue 4, part 2, 2026, pp. 109-122

ISSN 2220-6426 (Online), ISSN 2079-8156 (Print).

DOI: 10.15514/ISPRAS-2026-38(4)-21

For citation

Antipov Z.A. Methodology for Comparing and Analyzing the Security of Interrupt-Handling Subsystems in Operating-System Kernels and Their Resilience to Interrupt Storms. Proceedings of the Institute for System Programming, vol. 38, issue 4, part 2, 2026, pp. 109-122 DOI: 10.15514/ISPRAS-2026-38(4)-21.

Full text of the paper in pdf (in Russian) Back to the contents of the volume