跳至主導覽 跳至搜尋 跳過主要內容

CASE: Minimizing Attack Surfaces Based on Context-Aware System Call Enforcement

  • Man Ni Hsu
  • , Tsung Han Liu
  • , Hsuan Ying Lee
  • , Chun Ying Huang*
  • *此作品的通信作者

研究成果: Article同行評審

1 引文 斯高帕斯(Scopus)

摘要

Invoking system calls in exploit implementation is a typical approach to compromising a system. A key objective of these attacks is to manipulate program execution paths, with a specific focus on invoking targeted system calls. Our study introduces Context-Aware System Call Enforcement (CASE), a software-based approach meticulously crafted to shrink the attack surface associated with system call-based exploits. CASE achieves this by rigorously validating the context, mainly backward function call paths and runtime stack states, to ensure the legitimacy of system call invocations. Our strategy incorporates innovative elements, including anchored entry points, return address-based validation, and frame size checks. We formalize our approach by creating NP-hard challenges for potential attackers and complete with a proof-of-concept (PoC) implementation that shields against attacks. Our PoC implementation introduces minimal overhead, less than 2%, for context validation. Simultaneously, it adeptly identifies and halts attacks of varying complexities, ranging from simple examples to real-world servers.

原文English
頁(從 - 到)1952-1965
頁數14
期刊IEEE Transactions on Services Computing
18
發行號4
DOIs
出版狀態Published - 2025

指紋

深入研究「CASE: Minimizing Attack Surfaces Based on Context-Aware System Call Enforcement」主題。共同形成了獨特的指紋。

引用此