Validating the Integrity of Audit Logs Against Execution Repartitioning Attacks

Validating the Integrity of Audit Logs Against Execution Repartitioning Attacks
复制标题

DOI:
10.1145/3460120.3484551
复制
发表时间:
2021-11
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Carter Yagemann;Mohammad A. Noureddine;Wajih Ul Hassan;S. Chung;Adam Bates;Wenke Lee
Carter Yagemann;Mohammad A. Noureddine;Wajih Ul Hassan;S. Chung;Adam Bates;Wenke Lee
中科院分区:
其他
文献类型:
--
作者:
Carter Yagemann;Mohammad A. Noureddine;Wajih Ul Hassan;S. Chung;Adam Bates;Wenke Lee

文献摘要

被引文献

相似文献

事实证明,基于源头的审计日志因果分析是调查系统入侵的重要方法。然而,这种方法也存在依赖性爆炸的问题,即长期运行的进程会积累许多难以解开的依赖关系。执行单元分区通过将依赖关系分割成工作单元来解决这一问题,例如隔离处理单个 HTTP 请求的事件。不幸的是,我们发现,由于系统调用和应用程序日志信息被用于推断复杂的内部程序状态,当前的设计存在语义鸿沟问题。我们展示了攻击者如何修改现有的代码漏洞来控制事件分区,从而破坏攻击环节并陷害无辜用户。我们还展示了我们的技术如何规避现有的程序和日志完整性防御。然后,我们提出了一种新的执行单元分区设计,该设计利用额外的运行时数据来产生经过验证的分区,从而抵御操纵。我们的设计克服了最大限度减少额外开销的技术难题,同时将低级代码指令与高级审计事件准确地联系起来,部分原因是使用了商品硬件处理器跟踪技术。我们在 Linux 上实现了我们的设计原型 MARSARA,并在 14 个真实程序上对其进行了广泛评估,这些程序都是利用专家精心设计的漏洞攻击的目标。MARSARA 经过验证的分区成功捕获了所有攻击来源,在最坏情况下仅重新引入了 2.82% 的错误依赖关系,平均开销为 8.7%。我们使用一种名为 "分区攻击面"(Partitioning Attack Surface)的新指标表明,与 CFI 等完整性防御系统相比,MARSARA 在消除每个程序的重新分区小工具方面多出 47,642 个,这证明了我们原型的有效性及其所能防范攻击的新颖性。
Provenance-based causal analysis of audit logs has proven to be an invaluable method of investigating system intrusions. However, it also suffers from dependency explosion, whereby long-running processes accumulate many dependencies that are hard to unravel. Execution unit partitioning addresses this by segmenting dependencies into units of work, such as isolating the events that processed a single HTTP request. Unfortunately, we discover that current designs have a semantic gap problem due to how system calls and application log messages are used to infer complex internal program states. We demonstrate how attackers can modify existing code exploits to control event partitioning, breaking links in the attack and framing innocent users. We also show how our techniques circumvent existing program and log integrity defenses. We then propose a new design for execution unit partitioning that leverages additional runtime data to yield verified partitions that resist manipulation. Our design overcomes the technical challenges of minimizing additional overhead while accurately connecting low level code instructions to high level audit events, in part with the use of commodity hardware processor tracing. We implement a prototype of our design for Linux, MARSARA, and extensively evaluate it on 14 real-world programs, targeted with expertly crafted exploits. MARSARA's verified partitions successfully capture all the attack provenances while only reintroducing 2.82% of false dependencies, in the worst case, with an average overhead of 8.7%. Using a new metric called Partitioning Attack Surface, we show that MARSARA eliminates 47,642 more repartitioning gadgets per program than integrity defenses like CFI, demonstrating our prototype's effectiveness and the novelty of the attacks it prevents.