TY - JOUR
T1 - CASE
T2 - Minimizing Attack Surfaces Based on Context-Aware System Call Enforcement
AU - Hsu, Man Ni
AU - Liu, Tsung Han
AU - Lee, Hsuan Ying
AU - Huang, Chun Ying
N1 - Publisher Copyright:
© 2008-2012 IEEE.
PY - 2025
Y1 - 2025
N2 - Invoking system calls in exploit implementation is a typical approach to compromising a system. A key objective of these attacks is to manipulate program execution paths, with a specific focus on invoking targeted system calls. Our study introduces Context-Aware System Call Enforcement (CASE), a software-based approach meticulously crafted to shrink the attack surface associated with system call-based exploits. CASE achieves this by rigorously validating the context, mainly backward function call paths and runtime stack states, to ensure the legitimacy of system call invocations. Our strategy incorporates innovative elements, including anchored entry points, return address-based validation, and frame size checks. We formalize our approach by creating NP-hard challenges for potential attackers and complete with a proof-of-concept (PoC) implementation that shields against attacks. Our PoC implementation introduces minimal overhead, less than 2%, for context validation. Simultaneously, it adeptly identifies and halts attacks of varying complexities, ranging from simple examples to real-world servers.
AB - Invoking system calls in exploit implementation is a typical approach to compromising a system. A key objective of these attacks is to manipulate program execution paths, with a specific focus on invoking targeted system calls. Our study introduces Context-Aware System Call Enforcement (CASE), a software-based approach meticulously crafted to shrink the attack surface associated with system call-based exploits. CASE achieves this by rigorously validating the context, mainly backward function call paths and runtime stack states, to ensure the legitimacy of system call invocations. Our strategy incorporates innovative elements, including anchored entry points, return address-based validation, and frame size checks. We formalize our approach by creating NP-hard challenges for potential attackers and complete with a proof-of-concept (PoC) implementation that shields against attacks. Our PoC implementation introduces minimal overhead, less than 2%, for context validation. Simultaneously, it adeptly identifies and halts attacks of varying complexities, ranging from simple examples to real-world servers.
KW - Application security
KW - backward path validation
KW - minimizing attack surfaces
KW - system call
UR - https://www.scopus.com/pages/publications/105007534766
U2 - 10.1109/TSC.2025.3577497
DO - 10.1109/TSC.2025.3577497
M3 - Article
AN - SCOPUS:105007534766
SN - 1939-1374
VL - 18
SP - 1952
EP - 1965
JO - IEEE Transactions on Services Computing
JF - IEEE Transactions on Services Computing
IS - 4
ER -