Raksha: a flexible information flow architecture for software security

Raksha: a flexible information flow architecture for software security
复制标题

DOI:
10.1145/1250662.1250722
复制
发表时间:
2007-06
期刊:
--
影响因子:
--
通讯作者:
Michael Dalton;Hari Kannan;Christos Kozyrakis
Michael Dalton;Hari Kannan;Christos Kozyrakis
中科院分区:
其他
文献类型:
--
作者:
Michael Dalton;Hari Kannan;Christos Kozyrakis

文献摘要

被引文献

相似文献

高级语义漏洞(如SQL注入和跨站脚本)已超过缓冲区溢出,成为最普遍的安全漏洞。软件漏洞的广泛性和多样性要求新的安全解决方案将硬件方法的速度和实用性与软件系统的灵活性和鲁棒性相结合。提出了一种基于动态信息流跟踪(DIFT)的软件安全体系结构Raksha。Raksha提供了三个新颖的功能,允许灵活的硬件/软件安全方法。首先,它支持灵活和可编程的安全策略,使软件能够将硬件分析引导到广泛的高级和低级攻击。其次,它支持多个主动安全策略,可以保护系统免受并发攻击。第三,它支持低开销的安全处理程序,允许软件纠正、补充或扩展基于硬件的分析,而不会产生与操作系统陷阱相关的开销。我们提出了一个FPGA原型的Raksha,提供了一个功能齐全的Linux工作站的安全分析。使用未修改的二进制文件用于现实世界的应用程序,我们证明Raksha可以检测高级攻击,例如目录遍历、命令注入、SQL注入和跨站点脚本,以及低级攻击,例如缓冲区溢出。我们还表明,低开销异常处理是至关重要的分析,如内存损坏保护,以解决误报,由于频繁使用的软件中的不同代码模式发生。
High-level semantic vulnerabilities such as SQL injection and crosssite scripting have surpassed buffer overflows as the most prevalent security exploits. The breadth and diversity of software vulnerabilities demand new security solutions that combine the speed and practicality of hardware approaches with the flexibility and robustness of software systems. This paper proposes Raksha, an architecture for software security based on dynamic information flow tracking (DIFT). Raksha provides three novel features that allow for a flexible hardware/software approach to security. First, it supports flexible and programmable security policies that enable software to direct hardware analysis towards a wide range of high-level and low-level attacks. Second, it supports multiple active security policies that can protect the system against concurrent attacks. Third, it supports low-overhead security handlers that allow software to correct, complement, or extend the hardware-based analysis without the overhead associated with operating system traps. We present an FPGA prototype for Raksha that provides a full featured Linux workstation for security analysis. Using unmodified binaries for real-world applications, we demonstrate that Raksha can detect high-level attacks such as directory traversal, command injection, SQL injection, and cross-site scripting as well as low-level attacks such as buffer overflows. We also show that low overhead exception handling is critical for analyses such as memory corruption protection in order to address false positives that occur due to the diverse code patterns in frequently used software.