Preventing race condition attacks on file-systems

Preventing race condition attacks on file-systems
复制标题

防止对文件系统的竞争条件攻击

DOI:
10.1145/1066677.1066758
复制
发表时间:
2005
影响因子:
3.8
通讯作者:
A. Ray
A. Ray
中科院分区:
医学3区
文献类型:
--
作者:
P. Uppuluri;Uday Joshi;A. Ray

文献摘要

被引文献

相似文献

当一个过程在文件上执行操作顺序时,就会发生种族条件攻击,这是在“原子上”执行操作的假设。这可以通过恶意流程来利用,该过程通过受害者流程在两个连续的操作之间更改该文件的特征,从而诱使受害者流程在修改后的或Diflerent文件上操作。在本文中,我们提出了一种检测和防止这种种族条件攻击的实用方法。我们监视文件操作和强制执行策略,以防止通过流程进行任何连续文件操作之间的时间窗口。我们的方法不依赖于先前已知的攻击的知识。此外,我们在Linux上的实验表明,攻击可以用少于3%的错误警报检测到攻击,而性能开销少于流程执行时间的8%。
Race condition attacks occur when a process performs a sequence of operations on a file, under the assumption that the operations are being executed "atomically". This can be exploited by a malicious process which changes the characteristics of that file between two successive operations on it by a victim process, thus, inducing the victim process to operate on a modified or diflerent file. In this paper we present a practical approach to detect and prevent such race condition attacks. We monitor file operations and enforce policies which prevent the exploitation of the temporal window between any consecutive file operations by a process. Our approach does not rely on knowledge of previously known attacks. In addition, our experiments on Linux demonstrated that attacks can be detected with false alarms of less than 3% with performance overheads less than 8% of the processes execution time.