Playing for K(H)eaps: Understanding and Improving Linux Kernel Exploit Reliability

Playing for K(H)eaps: Understanding and Improving Linux Kernel Exploit Reliability
复制标题

DOI:
--
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Kyle Zeng;Yueqi Chen;Haehyun Cho;Xinyu Xing;Adam Doupé;Yan Shoshitaishvili;Tiffany Bao
Kyle Zeng;Yueqi Chen;Haehyun Cho;Xinyu Xing;Adam Doupé;Yan Shoshitaishvili;Tiffany Bao
中科院分区:
其他
文献类型:
--
作者:
Kyle Zeng;Yueqi Chen;Haehyun Cho;Xinyu Xing;Adam Doupé;Yan Shoshitaishvili;Tiffany Bao

文献摘要

被引文献

相似文献

LINUX内核堆布局的动态化明显影响了内核堆攻击的可靠性,这使得可开发性评估变得具有挑战性。尽管过去有人提出了稳定漏洞的技术,但很少有人进行科学研究来评估它们的有效性,并探索它们的工作条件。本文对内核堆开发的可靠性问题进行了系统的研究。我们fi首先采访了内核安全专家,收集了常用的漏洞稳定技术和专家对这些技术的意见。然后,我们在17个真实的内核堆漏洞上评估了这些稳定技术。结果表明,许多内核安全专家对漏洞稳定技术的看法是错误的。为了帮助安全社区更好地了解攻击稳定性,我们检查了我们的实验结果,并设计了一个通用的内核堆攻击模型。我们使用所提出的利用模型来解释利用不可靠性问题,并分析稳定技术成功或失败的原因。我们还利用该模型提出了一种新的开发技术。实验表明,新的稳定技术使Linux内核攻击的可靠性平均提高了14.87%。将这一新提出的技术与现有的稳定方法相结合,得到了一种复合稳定方法,其利用可靠性平均提高了135.53%,比专业安全研究人员的利用稳定方法高出36.07%。
The dynamic of the Linux kernel heap layout significantly impacts the reliability of kernel heap exploits, making ex-ploitability assessment challenging. Though techniques have been proposed to stabilize exploits in the past, little scientific research has been conducted to evaluate their effectiveness and explore their working conditions. In this paper, we present a systematic study of the kernel heap exploit reliability problem. We first interview kernel security experts, gathering commonly adopted exploitation stabilization techniques and expert opinions about these techniques. We then evaluate these stabilization techniques on 17 real-world kernel heap exploits. The results indicate that many kernel security experts have incorrect opinions on exploitation stabilization techniques. To help the security community better understand exploitation stabilization, we inspect our experiment results and design a generic kernel heap exploit model. We use the proposed exploit model to interpret the exploitation unreliability issue and analyze why stabilization techniques succeed or fail. We also leverage the model to propose a new exploitation technique. Our experiment indicates that the new stabilization technique improves Linux kernel exploit reliability by 14.87% on average. Combining this newly proposed technique with existing stabilization approaches produces a composite stabilization method that achieves a 135.53% exploitation reliability improvement on average, outperforming exploit stabilization by professional security researchers by 36.07%.