Decap: Deprivileging Programs by Reducing Their Capabilities

Decap: Deprivileging Programs by Reducing Their Capabilities
复制标题

Decap:通过降低程序的能力来剥夺程序的特权

DOI:
10.1145/3545948.3545978
复制
发表时间:
2022
期刊:
Intrusions and Defenses (RAID
影响因子:
--
通讯作者:
Polychronakis, Michalis
Polychronakis, Michalis
中科院分区:
--
文献类型:
--
作者:
Hasan, Md Mehedi;Ghavamnia, Seyedhamed;Polychronakis, Michalis

文献摘要

参考文献

被引文献

相似文献

Linux允许非root用户通过使用setuid(“set user ID”)机制执行某些特权操作。这明显违反了最小特权原则,因为setuid程序是在完全超级用户权限下运行的,一旦发现其中的漏洞,就会带来灾难性的后果。Linux的功能旨在通过将超级用户权限划分为可以单独分配的不同单元来改善这种情况。尽管这些功能在降低特权升级风险方面有明显的好处,但它们的实际使用却很少,而且setuid程序在现代Linux发行版中仍然很流行。缺乏一个系统的方法,开发人员来确定所需的功能,由一个给定的程序是一个促成因素,阻碍了他们的application.In本文中,我们提出Decap,二进制代码分析工具,自动解除特权的程序,通过识别的能力,他们需要基于系统调用,他们可能会调用的子集。这是通过我们系统性的努力实现的,我们在所有与特权操作相关的Linux系统调用和它们所依赖的相应功能之间导出了一个完整的映射。我们对一组201个setuid程序进行的实验评估结果表明,Decap在有意义地对它们进行去重方面是有效的,其中一半的程序需要少于16个功能,69%的程序避免使用安全关键的CAP_REQ_ADMIN功能。
Linux enables non-root users to perform certain privileged operations through the use of the setuid (“set user ID”) mechanism. This represents a glaring violation of the principle of least privilege, as setuid programs run with full superuser privileges—with disastrous outcomes when vulnerabilities are found in them. Linux capabilities aim to improve this situation by splitting superuser privileges into distinct units that can be assigned individually. Despite the clear benefits of capabilities in reducing the risk of privilege escalation, their actual use is scarce, and setuid programs are still prevalent in modern Linux distributions. The lack of a systematic way for developers to identify the capabilities needed by a given program is a contributing factor that hinders their applicability.In this paper we present Decap, a binary code analysis tool that automatically deprivileges programs by identifying the subset of capabilities they require based on the system calls they may invoke. This is made possible by our systematic effort in deriving a complete mapping between all Linux system calls related to privileged operations and the corresponding capabilities on which they depend. The results of our experimental evaluation with a set of 201 setuid programs demonstrate the effectiveness of Decap in meaningfully deprivileging them, with half of them requiring fewer than 16 capabilities, and 69% of them avoiding the use of the security-critical CAP_SYS_ADMIN capability.
DOI: 10.1145/3359789.3359823
发表时间: 2019-12
期刊: Proceedings of the 35th Annual Computer Security Applications Conference
影响因子: --
作者:
Ioannis Agadakos;Di Jin;David Williams-King;V. Kemerlis;G. Portokalidis
通讯作者: Ioannis Agadakos;Di Jin;David Williams-King;V. Kemerlis;G. Portokalidis
并行和分布式计算和网络
DOI: --
发表时间: 2011
期刊:
影响因子: --
作者:
Luo Qi
通讯作者: Luo Qi
DOI: 10.1145/3471621.3471839
发表时间: 2021-10
期刊: Proceedings of the 24th International Symposium on Research in Attacks, Intrusions and Defenses
影响因子: --
作者:
Nick Roessler;Lucas Atayde;I. Palmer;D. McKee;J. Pandey;V. Kemerlis;Mathias Payer;Adam Bates;Jonathan M. Smith;A. DeHon;Nathan Dautenhahn
通讯作者: Nick Roessler;Lucas Atayde;I. Palmer;D. McKee;J. Pandey;V. Kemerlis;Mathias Payer;Adam Bates;Jonathan M. Smith;A. DeHon;Nathan Dautenhahn
配置驱动的软件膨胀
DOI: 10.1145/3301417.3312501
发表时间: 2019
期刊: Proceedings of the 12th European Workshop on System Security (EuroSec
影响因子: --
作者:
Koo, Hyungjoon;Ghavamnia, Seyedhamed;Polychronakis, Michalis
通讯作者: Polychronakis, Michalis
具有声明式、临时性和实用编程功能
DOI: --
发表时间: 2013
期刊: IEEE Symposium on Security and Privacy
影响因子: --
作者:
William R. Harris;S. Jha;T. Reps;Jonathan Anderson;R. Watson
通讯作者: R. Watson