Dynamic Library Compartmentalization

Dynamic Library Compartmentalization
复制标题

动态库划分

DOI:
10.1145/3618305.3623604
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
Larose O
Larose O
中科院分区:
--
文献类型:
--
作者:
Larose O

文献摘要

相似文献

软件由具有不同目标的不同部分组成,每个部分都有不同的需求。从安全角度来看,这意味着不一定需要相同的权限:隔离某些代码可能是有益的,这样它可以遵循最小特权原则对进程进行有限的控制。如果没有任何类型的划分,应用程序敏感部分中发现的漏洞意味着整个进程可能会被破坏,因为它的整个内存现在都开放供攻击者读取和修改。危险代码的一个值得注意的例子是使用外部库:使用库意味着它是受信任的,因为它在程序的上下文中运行,因此可以读取和修改任何程序状态。这意味着恶意或易受攻击的代码可以通过这种方式引入系统,从而危及进程内存中存在的敏感信息。这就引出了一个问题:如果软件的某些部分不一定是可信的,我们可以做什么来限制它们在整个过程中的能力?我们提出了一种新的库沙箱方法,重点关注隔离动态加载的库。虽然现有方法通常利用静态分析在源代码级别和构建期间执行检测,但我们力求完全在程序运行时期间工作。
Software is composed of different parts with different goals, each with different needs. Security-wise, this means not all necessarily need the same permissions: it can be beneficial to isolate some code such that it has limited control over the process, following the principle of least privilege. Without any sort of compartmentalization, a vulnerability found in a sensitive part of an application means the entire process can get corrupted, as its entire memory is now open to be read and modified by the attacker.One notable example of dangerous code is the use of external libraries: using a library implies that it is trusted, as it is run within the program's context and can therefore read and modify any program state. This means malicious or vulnerable code can be introduced to the system this way, which can compromise sensitive information that is present in the process' memory. This begs the question: if parts of the software cannot necessarily be trusted, what can we do to limit their capabilities over the process?We propose a new library sandboxing approach, focusing on isolating dynamically loaded libraries. While existing approaches usually leverage static analysis to perform instrumentation at the source level and during build time, we instead strive to work entirely during the program's run time.