CIVSCOPE: Analyzing Potential Memory Corruption Bugs in Compartment Interfaces

CIVSCOPE: Analyzing Potential Memory Corruption Bugs in Compartment Interfaces
复制标题

CIVSCOPE:分析隔间接口中潜在的内存损坏错误

DOI:
10.1145/3625275.3625399
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
Chien Y
Chien Y
中科院分区:
--
文献类型:
--
作者:
Chien Y

文献摘要

参考文献

相似文献

分隔化将程序分解为单独的部分,通过分隔接口进行交互-隐藏信息,否则可以从受损组件访问。不幸的是,大多数代码都没有将其接口作为信任边界来开发。如果不加检查,这些接口暴露混乱的代理攻击,从恶意输入的数据流可以强制一个车厢进入访问以前隐藏的信息,代表不受信任的caller.We引入一种新的程序分析模型,通过车厢接口的数据流,自动和全面地找到和测量从车厢绕过数据流的攻击面。使用这种分析,我们检查Linux内核沿着不同的隔间边界和特征的脆弱性程度。我们发现有许多隔间旁路路径(395/4394驱动器接口有22741个路径),无法手动校正。我们介绍CIVSCOPE作为一个全面的和健全的方法来分析和发现下限和潜在的上限与隔间边界接口的内存操作的风险。
Compartmentalization decomposes a program into separate parts with mediated interactions through compartment interfaces---hiding information that would otherwise be accessible from a compromised component. Unfortunately, most code was not developed assuming its interfaces as trust boundaries. Left unchecked, these interfaces expose confused deputy attacks where data flowing from malicious inputs can coerce a compartment into accessing previously hidden information on-behalf-of the untrusted caller.We introduce a novel program analysis that models data flows through compartment interfaces to automatically and comprehensively find and measure the attack surface from compartment bypassing data flows. Using this analysis we examine the Linux kernel along diverse compartment boundaries and characterize the degree of vulnerability. We find that there are many compartment bypassing paths (395/4394driver interfaces have22741paths), making it impossible to correct by hand. We introduce CIVSCOPE as a comprehensive and sound approach to analyze and uncover the lower-bound and potential upper-bound risks associated with the memory operations in compartment boundary interfaces.
DOI: 10.1145/3445814.3446731
发表时间: 2021-04
期刊: Proceedings of the 26th ACM International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子: --
作者:
V. Sartakov;Lluís Vilanova;P. Pietzuch
通讯作者: V. Sartakov;Lluís Vilanova;P. Pietzuch
DOI: 10.1145/3471621.3471839
发表时间: 2021-10
期刊: Proceedings of the 24th International Symposium on Research in Attacks, Intrusions and Defenses
影响因子: --
作者:
Nick Roessler;Lucas Atayde;I. Palmer;D. McKee;J. Pandey;V. Kemerlis;Mathias Payer;Adam Bates;Jonathan M. Smith;A. DeHon;Nathan Dautenhahn
通讯作者: Nick Roessler;Lucas Atayde;I. Palmer;D. McKee;J. Pandey;V. Kemerlis;Mathias Payer;Adam Bates;Jonathan M. Smith;A. DeHon;Nathan Dautenhahn
FlexOS:使操作系统隔离变得灵活
DOI: 10.1145/3458336.3465292
发表时间: 2021
期刊: Proceedings of the Workshop on Hot Topics in Operating Systems
影响因子: --
作者:
Hugo Lefeuvre;Vlad;Stefan Teodorescu;Pierre Olivier;Tiberiu Mosnoi;R. Deaconescu;Felipe Huici;C. Raiciu
通讯作者: C. Raiciu
使用 HAKC 防止内核黑客攻击
DOI: 10.14722/ndss.2022.24026
发表时间: 2022
期刊: Proceedings 2022 Network and Distributed System Security Symposium
影响因子: --
作者:
D. McKee;Yianni Giannaris;Carolina Ortega;Howie Shrobe;Mathias Payer;Hamed Okhravi;N. Burow
通讯作者: N. Burow
内核扩展验证站不住脚
DOI: 10.1145/3593856.3595892
发表时间: 2023
期刊: ACM
影响因子: --
作者:
Jia, Jinghao;Sahu, Raj;Oswald, Adam;Williams, Dan;Le, Michael V.;Xu, Tianyin
通讯作者: Xu, Tianyin