https://highassurance.rs/ 1. High Assurance Rust 2. Frequently Asked Questions (FAQ) 3. Engage with this Book! 4. Sponsor Call for Proposals (CFP) 5. Changelog 6. License 7. 8. Novice: Systems Security 9. 10. 1. Introduction 11. 1. 1.1. Why this book? 2. 1.2. How is this book structured? 3. 1.3. Hands-on Learning 4. 1.4. About the Team 5. 1.5. Warmup: Environment Setup 12. 2. Software Assurance 13. 1. 2.1. Static vs. Dynamic Tools 2. 2.2. Static Assurance (1/2) 3. 2.3. Static Assurance (2/2) 4. 2.4. Dynamic Assurance (1/3) 5. 2.5. Dynamic Assurance (2/3) 6. 2.6. Dynamic Assurance (3/3) 7. 2.7. Limitations and Threat Modeling 8. 2.8. DIY CLI Encryption Tool 9. 2.9. Operational Assurance (1/2) 10. 2.10. Operational Assurance (2/2) 11. 2.11. Challenge: Extend the CLI Tool 14. 3. Rust Zero-Crash Course 15. 1. 3.1. On Undefined Behavior 2. 3.2. Rust: Low-Level Data (1/6) 3. 3.3. Rust: High-Level Data (2/6) 4. 3.4. Rust: Control Flow (3/6) 5. 3.5. Rust: Ownership Principles (4/6) 6. 3.6. Rust: Ownership in Practice (5/6) 7. 3.7. Rust: Error Handling (6/6) 8. 3.8. The Module System 9. 3.9. Recommended Tooling 10. 3.10. Rust's Release Cycle 11. 3.11. Challenge: Port a Program 16. 4. Understanding Memory 17. 1. 4.1. A Software Perspective 2. 4.2. An Attacker's Perspective 3. 4.3. Rust's Memory Safety Guarantees 4. 4.4. Integer Representation Issues 5. 4.5. The #![no_std] Attribute 6. 4.6. Case Study: Real-world Rust CVEs 7. 4.7. Debugging with Mozilla rr 8. 4.8. Writing an Exploit 9. 4.9. Challenge: TODO 18. 19. Advanced Beginner: Core Project 20. 21. 5. Binary Search Tree (BST) Basics 22. 1. 5.1. Core BST Operations in Python 2. 5.2. Problems Translating to Rust 3. 5.3. The Importance of Balance 4. 5.4. TODO 5. 5.5. Challenge: TODO 23. 6. Building an Arena Allocator 24. 1. 6.1. Let's Talk Allocators 2. 6.2. A Stack-Only Arena 3. 6.3. Index-based Data Structures 4. 6.4. TODO 5. 6.5. Challenge: TODO 25. 7. A Self-balancing BST 26. 1. 7.1. Interface-relevant Traits 2. 7.2. Scapegoat Trees 3. 7.3. Insert 4. 7.4. Remove 5. 7.5. Find 6. 7.6. Challenge: TODO 27. 8. Digital Twin Testing 28. 1. 8.1. Basic QEMU Internals 2. 8.2. How Semi-hosting Works 3. 8.3. CLI REPL Harness 4. 8.4. Limitations 5. 8.5. TODO 6. 8.6. Challenge: TODO 29. 9. Building Maps and Sets 30. 1. 9.1. TODO 2. 9.2. Challenge: TODO 31. 10. Implementing Iterators 32. 1. 10.1. TODO 2. 10.2. Challenge: TODO 33. 34. Competent: Validation and Deployment 35. 36. 11. Static Verification 37. 1. 11.1. An Introduction to 1st Order Logic 2. 11.2. Proving Absence of Panics 3. 11.3. Deductively Verifying our Arena Allocator 4. 11.4. Model Checking for unsafe Code 5. 11.5. TODO 6. 11.6. Challenge: Prove a Sorting Algorithm 38. 12. Dynamic Testing 39. 1. 12.1. Introduction to Coverage-Guided Fuzzing 2. 12.2. Building a Differential Fuzzing Harness 3. 12.3. Using Miri to Detect Undefined Behavior 4. 12.4. Benchmarking and Optimization 5. 12.5. TODO 6. 12.6. Challenge: Bug-hunting with Fuzzers 40. 13. Operational Deployment 41. 1. 13.1. Understanding unsafe (1/3) 2. 13.2. Understanding unsafe (2/3) 3. 13.3. Understanding unsafe (3/3) 4. 13.4. CFFI 101 5. 13.5. C99 Interoperability 6. 13.6. Python3 Interoperability 7. 13.7. Runtime Balance Reconfiguration 8. 13.8. TODO 9. 13.9. Challenge: TODO 42. 14. Maximizing Assurance 43. 1. 14.1. Rust Security Research 2. 14.2. Rust's Limitations 3. 14.3. Best Practices Beyond Rust 4. 14.4. TODO 5. 14.5. Challenge: TODO 44. 45. Conclusion 46. 47. 15. Review 48. 1. 15.1. Key Concepts 2. 15.2. Key Blue-Team Skills 3. 15.3. Key Red-Team Skills 49. 16. Appendix 50. 1. 16.1. Setup: Using our Docker Container 2. 16.2. Inventory: Tools of the Trade 3. 16.3. Inventory: Recommended Reading 4. 16.4. Inventory: Additional Resources 5. 16.5. Fundamentals: Stream Ciphers 6. 16.6. Fundamentals: Type Systems 7. 16.7. Fundamentals: Component-Based Design 8. 16.8. Fundamentals: Memory Hierarchy 9. 16.9. Fundamentals: Dynamic Linking 10. 16.10. Misc: Size Optimization 11. 16.11. Misc: The Typestate Pattern 12. 16.12. Misc: C++ Interoperability 13. 16.13. Misc: Compile-time Metaprogramming * Light (default) * Rust * Coal * Navy * Ayu High Assurance Rust: Developing Secure and Robust Software [ ] High Assurance Rust High Assurance Rust Developing Secure and Robust Software --------------------------------------------------------------------- This book is an introduction to building performant software we can justifiably trust. That means having sufficient data to support confidence in our code's functionality and security. Trustworthiness is a hallmark of high assurance software. With assurance as our driving concept, we'll take a hands-on, project-based approach to two fundamental but often inaccessible topics in software development: systems programming and low-level software security. You'll learn Rust - a modern, multi-paradigm language that emphasizes speed and correctness. Most programming books teach a new language by presenting a dozen small, unrealistic programs. Not this one. We'll design, write, and validate a fully-featured alternative to the ordered map and set implementations in Rust's standard library. You'll gain a deep understanding of the Rust language by re-implementing one of its major dynamic collections, one idiomatic API at a time. Unlike the standard version, our implementation will be: * Maximally Safe. Upholds Rust's strongest memory safety guarantees, for all possible executions. + To test properties the compiler can't prove, we'll learn advanced program analysis techniques, including differential fuzzing and deductive verification*. * Extremely Portable. Capable of running on every operating system, or even without one (e.g. "bare metal"). + Our library is a hardened component. To integrate it within larger codebases, we'll add CFFI bindings to make the Rust functions callable from other languages - including C and Python. * Highly Available. Offers fallible APIs for handling cases that could otherwise result in a crash. + E.g. Out-of-Memory (OOM) error - when all pre-allocated memory has been exhausted. The State-of-the-Art in Practical Software Assurance We'll use cutting-edge, open-source software assurance tools to validate the code we write in this book. Some of these tools are mature and used in commercial industry: * rustc (modern compiler) * libFuzzer (fuzz testing framework) * rr ("time-travel" debugger) * qemu (whole-system emulator) Other tools are experimental and under active research. A full inventory is available in the appendix. Visually, this book covers the below topics (contrasted roughly on tradeoff of development speed and formal rigor). Don't worry, we'll provide clear explanations and context for each. Notice the bias toward development speed. We're interested in lightweight processes that, in the long run, enable us ship quality code faster and spend less time patching security and reliability failures. Techniques you can apply to real-world code. Today. Assurance Techniques Unlike other Rust books, you won't just learn the language. You'll learn how to reason about software security at the leading edge. To think like an attacker. And to write code resistant to attack. That mental model is valuable no matter what programming language you primarily use. You need to build a data structure library to serve a mission-critical application. It must run on nearly any device, operate in the field for years on end without error, and tolerate attacker-controlled input. There will be no patches and there can be no failures. Your code must survive. Ship strong. --------------------------------------------------------------------- * == may be subject to change! This book is a work in progress. If you're like to be notified when it's finished and a physical print is available, please sign up here.