首页> 外文会议>ACM symposium on Applied computing >Preventing race condition attacks on file-systems
【24h】

Preventing race condition attacks on file-systems

机译:防止对文件系统的竞争状况攻击

获取原文

摘要

Race condition attacks occur when a process performs a sequence of operations on a file, under the assumption that the operations are being executed "atomically". This can be exploited by a malicious process which changes the characteristics of that file between two successive operations on it by a victim process, thus, inducing the victim process to operate on a modified or diflerent file. In this paper we present a practical approach to detect and prevent such race condition attacks. We monitor file operations and enforce policies which prevent the exploitation of the temporal window between any consecutive file operations by a process. Our approach does not rely on knowledge of previously known attacks. In addition, our experiments on Linux demonstrated that attacks can be detected with false alarms of less than 3% with performance overheads less than 8% of the processes execution time.
机译:当进程在文件上执行一系列操作时(假设操作是“原子地”执行的),就会发生竞争条件攻击。这可以被恶意进程利用,该恶意进程在受害进程对其进行的两次连续操作之间更改该文件的特性,从而诱使受害进程对修改后的文件或不同的文件进行操作。在本文中,我们提出了一种实用的方法来检测和防止此类种族条件攻击。我们监视文件操作并执行策略,以防止进程利用任何连续文件操作之间的时间窗口。我们的方法不依赖于先前已知的攻击知识。此外,我们在Linux上进行的实验表明,可以用少于3%的错误警报检测攻击,而性能开销少于进程执行时间的8%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号