首页> 外文会议>IEEE Conference on Dependable and Secure Computing >Additional Kernel Observer to Prevent Privilege Escalation Attacks by Focusing on System Call Privilege Changes
【24h】

Additional Kernel Observer to Prevent Privilege Escalation Attacks by Focusing on System Call Privilege Changes

机译:通过关注系统调用特权更改来防止特权升级攻击的其他内核观察者

获取原文

摘要

In recent years, there has been an increase in attacks that exploit operating system vulnerabilities. In particular, if an administrator's privilege is acquired by an attacker through a privilege escalation attack, the attacker can operate the entire system and the system can suffer serious damage. In this paper, an additional kernel observer (AKO) method is proposed. It prevents privilege escalation attacks that exploit operating system vulnerabilities. We focus on the fact that a process privilege can be changed only by specific system calls. AKO monitors privilege information changes during system call processing. If AKO detects a privilege change after system call processing, whereby the invoked system call does not originally change the process privilege, AKO regards the change as a privilege escalation attack and applies countermeasures against it. In this paper, we describe the design and implementation of AKO for Linux x86, 64 bit. Moreover, AKO can be expanded to prevent the falsification of various data in the kernel space. We present an expansion example that prevents the invalidation of Security-Enhanced Linux. Evaluation results show that AKO is effective against privilege escalation attacks, while maintaining low overhead.
机译:近年来,利用操作系统漏洞的攻击有所增加。特别是,如果攻击者通过特权升级攻击获得了管理员的特权,则攻击者可以操作整个系统,并且系统可能遭受严重破坏。在本文中,提出了一种附加的内核观察器(AKO)方法。它可以防止利用操作系统漏洞的特权升级攻击。我们关注一个事实,即只能通过特定的系统调用才能更改进程特权。 AKO监视系统调用处理期间的特权信息更改。如果AKO在系统调用处理后检测到特权更改,从而被调用的系统调用最初并未更改进程特权,则AKO将更改视为特权升级攻击,并对其采取对策。在本文中,我们描述了用于Linux x86(64位)的AKO的设计和实现。而且,可以扩展AKO来防止内核空间中各种数据的伪造。我们提供一个扩展示例,以防止使安全性增强的Linux失效。评估结果表明,AKO对特权提升攻击有效,同时保持较低的开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号