Sifter: Protecting Security-Critical Kernel Modules in Android through Attack Surface Reduction

Sifter: Protecting Security-Critical Kernel Modules in Android through Attack Surface Reduction
复制标题

Sifter:通过减少攻击面来保护 Android 中的安全关键内核模块

DOI:
10.1145/3495243.3560548
复制
发表时间:
2022
期刊:
ACM MobiCom
影响因子:
--
通讯作者:
Amiri Sani, Ardalan
Amiri Sani, Ardalan
中科院分区:
--
文献类型:
--
作者:
Hung, Hsin-Wei;Liu, Yingtong;Amiri Sani, Ardalan

文献摘要

相似文献

Linux内核是使用Android操作系统的移动终端的可信计算基础(TCB)的重要组成部分,这使得它对攻击者具有吸引力。虽然内核中的所有漏洞都很重要,但那些可被不受信任的程序直接访问的漏洞构成了严重的威胁。本文介绍了Sifter,一种用于保护安全关键内核模块的解决方案,即,这些模块直接暴露给不受信任的程序。Sifter的关键方法是使用细粒度、高选择性的过滤器来减少这些内核模块的攻击面,并使不受信任的程序无法访问它们的漏洞。Sifter中的关键观察是,合法程序如何向这些内核模块发出系统调用有丰富的模式;因此可以生成只允许这种系统调用模式的过滤器,并因此减轻脆弱性(包括零日的),只能利用非正统的系统调用模式。我们报告了一个原型的Sifter,并用它来生成过滤器的两个安全-许多移动的设备中使用的关键内核模块:高通KGSL GPU设备驱动程序和Binder IPC。我们对这两个模块中的41个最近的CVE进行了详细的研究和评估,结果表明Sifter能够在不优先了解这些漏洞的情况下减轻大约一半的系统调用触发的漏洞。此外,我们的评估表明,当使用足够多的合法程序来生成给定模块的过滤器策略时,过滤器的误报率为0%。最后,我们对这些过滤器的实验表明,尽管对系统调用进行了许多细粒度的检查,Sifter对真实的程序增加了非常小或可以忽略的性能开销,并且产生了非常少量的能量消耗。
The Linux kernel is an important part of the Trusted Computing Base (TCB) of a mobile device using the Android OS, making it attractive to attackers. While all vulnerabilities in the kernel are important, those thatare directly reachable by untrusted programspose a grave threat. This paper introduces Sifter, a solution for protecting security-critical kernel modules, i.e., those modules that are directly exposed to untrusted programs. Sifter's key approach is the use of fine-grained, highly-selective filters to reduce the attack surface of these kernel modules and make their vulnerabilities unreachable for untrusted programs. The key observation in Sifter is that there are rich patterns in how legitimate programs issue syscalls to these kernel modules; thus, one can generate filters that only allow such syscall patterns, and as a result mitigate vulnerabilities (including zero-day ones) that could only be exploited by the use of unorthodox syscall patterns.We report a prototype of Sifter and use it to generate filters for two security-critical kernel modules used in many mobile devices: Qualcomm KGSL GPU device driver and Binder IPC. Our detailed study and evaluation of 41 recent CVEs in these two modules show that Sifter is capable of mitigating about half of all syscall-triggered vulnerabilities withouta prioriknowledge of these vulnerabilities. Moreover, our evaluation shows that when using an adequately large number of legitimate programs to generate the filter policies for a given module, the filter's false positive rate goes to 0%. Finally, our experiments with these filters show that, despite numerous finegrained checks on syscalls, Sifter adds a very small or negligible performance overhead to real programs and incurs a very small amount of energy consumption.