首页> 外文会议>ACM symposium on access control models and technologies >Towards Analyzing Complex Operating System Access Control Configurations
【24h】

Towards Analyzing Complex Operating System Access Control Configurations

机译:在分析复杂的操作系统访问控制配置

获取原文

摘要

An operating system relies heavily on its access control mechanisms to defend against local and remote attacks. The complexities of modern access control mechanisms and the scale of possible configurations are often overwhelming to system administrators and software developers. Therefore mis-configurations are very common and the security consequences are serious. Given the popularity and uniqueness of Microsoft Windows systems, it is critical to have a tool to comprehensively examine the access control configurations. However, current studies on Windows access control mechanisms are mostly based on known attack patterns. We propose a tool, WACCA, to systematically analyze the Windows configurations. Given the attacker's initial abilities and goals, WACCA generates an attack graph based on interaction rules. The tool then automatically generates attack patterns from the attack graph. Each attack pattern represents attacks of the same nature. The attack subgraphs and instances are also generated for each pattern. Compared to existing solutions, WACCA is more comprehensive and does not rely on manually defined attack patterns. It also has a unique feature in that it models software vulnerabilities and therefore can find attacks that rely on exploiting these vulnerabilities. We study two attack cases on a Windows Vista host and discuss the analysis results.
机译:操作系统严重依赖于其访问控制机制来防御本地和远程攻击。现代访问控制机制的复杂性和可能配置的规模通常是系统管理员和软件开发人员的压倒性。因此,MIS-Configurations非常普遍,安全后果严重。鉴于Microsoft Windows系统的流行度和唯一性,有一个工具可以全面检查访问控制配置至关重要。然而,目前关于Windows访问控制机制的研究主要基于已知的攻击模式。我们提出了一种工具WACCA来系统地分析Windows配置。鉴于攻击者的初始能力和目标,WACCA基于交互规则生成攻击图。然后,该工具从攻击图自动生成攻击模式。每个攻击模式代表相同性质的攻击。每个模式也会生成攻击子图和实例。与现有解决方案相比,WACCA更全面,并不依赖手动定义攻击模式。它还具有一个独特的功能,因为它模拟了软件漏洞,因此可以找到依赖于利用这些漏洞的攻击。我们在Windows Vista主机上研究了两个攻击案例,并讨论了分析结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号