The devil is in the detail: Generating system call whitelist for Linux seccomp

The devil is in the detail: Generating system call whitelist for Linux seccomp
复制标题

细节决定成败:为 Linux seccomp 生成系统调用白名单

DOI:
10.1016/j.future.2022.04.016
复制
发表时间:
2022
期刊:
Future Generation Computer Systems
影响因子:
--
通讯作者:
Wan, Shengye
Wan, Shengye
中科院分区:
--
文献类型:
--
作者:
Xing, Yunlong;Cao, Jiahao;Sun, Kun;Yan, Fei;Wan, Shengye

文献摘要

参考文献

被引文献

相似文献

系统调用为用户进程提供了请求内核服务的主接口,然而,对于任何特定的进程,大多数都不需要。如果一个用户进程受到威胁,那么这些不必要的系统调用就会被滥用来攻击内核和其他进程。为了解决这个问题,seccomp机制已经被合并到Linux内核中,以根据系统调用白名单来限制可用的系统调用。然而,自动有效地为特定用户进程生成最小但完整的系统调用白名单仍然是一个挑战。本文开发了一个工具包TAILOR,它主要依靠静态分析,在源代码分析的基础上,为标准库生成从库函数到其对应的系统调用的映射表。然后对于任何通过标准库调用系统调用的应用程序,我们只需将应用程序中调用的库函数与映射表进行比较,即可获得所需的系统调用。TAILOR解决了源代码级标准库分析中存在的宏函数识别困难、宏别名导致的调用树不成链、静态分析难以识别函数作用域等问题。对50个常用的通用终端命令的实验表明,该工具可以减少88%的系统调用,并阻止约74%的恶意系统调用的潜在漏洞。
The system calls provide the main interface for user processes to request the kernel services, however, for any specific process, most of them will not be needed. If a user process is compromised, those unnecessary system calls can be abused to attack the kernel and the other processes. To migrate this problem, the seccomp mechanism has been merged into the Linux kernel to limit the available system calls according to a system call whitelist. However, it is still a challenge to automatically and effectively generate a minimal but complete system call whitelist for a specific user process. In this paper, we develop a toolkit named TAILOR that mainly relies on the static analysis to generate a mapping table for the standard library from the library functions to their corresponding system calls based on the source code analysis. Then for any application that invokes system calls via the standard library, we can just compare the called library functions in the application with the mapping table to obtain required system calls. TAILOR solves the problems during source-level standard library analysis, which consist of the difficulty in macro function identification, unchained calling tree caused by macro aliases, and the difficulty in identifying the function scope via static analysis. Our experiments on 50 popular general terminal commands show that our tool can reduce 88% system calls for them and block about 74% potential vulnerabilities from malicious system calls.
DOI: --
发表时间: 2017
期刊: --
影响因子: --
作者:
Jiang Ming;Dongpeng Xu;Yufei Jiang;Dinghao Wu
通讯作者: Jiang Ming;Dongpeng Xu;Yufei Jiang;Dinghao Wu
DOI: 10.1016/j.exer.2017.06.020
发表时间: 2017-10
影响因子: 3.4
作者:
Butovich IA
通讯作者: Butovich IA