K-LEAK: Towards Automating the Generation of Multi-Step Infoleak Exploits against the Linux Kernel

K-LEAK: Towards Automating the Generation of Multi-Step Infoleak Exploits against the Linux Kernel
复制标题

DOI:
10.14722/ndss.2024.24935
复制
发表时间:
2024
期刊:
Proceedings 2024 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Zhengchuan Liang;Xiaochen Zou;Chengyu Song;Zhiyun Qian
Zhengchuan Liang;Xiaochen Zou;Chengyu Song;Zhiyun Qian
中科院分区:
其他
文献类型:
--
作者:
Zhengchuan Liang;Xiaochen Zou;Chengyu Song;Zhiyun Qian

文献摘要

相似文献

- 操作系统内核中的信息泄漏(简称信息泄漏)的严重性不可低估,已经提出了各种利用技术来实现操作系统内核中的信息泄漏。其中,基于内存错误的信息泄漏是强大的,广泛用于现实世界的利用。然而,现有的方法来发现基于内存错误的信息泄漏缺乏系统的推理,其搜索空间,并没有充分探索的搜索空间。因此,它们无法利用内核中的大量内存错误。根据内存错误的理论模型,这种方法的实际搜索空间是巨大的,因为在开发过程中可能涉及多个步骤,并且几乎任何内存错误都可以被利用来实现信息泄漏。为了弥合理论与现实之间的差距,我们提出了一个框架K-LEAK,以方便在Linux内核中生成基于内存错误的信息泄漏漏洞。K-LEAK将信息泄漏攻击生成视为数据流搜索问题。通过对内存错误引入的非预期数据流以及现有内存错误如何创建新内存错误进行建模,K-LEAK可以以多步方式系统地搜索信息泄漏数据流路径。我们实现了一个原型的K-LEAK和评估它与内存错误syzbot和CVE。评估结果证明了K-LEAK在使用各种多步骤策略生成各种信息漏洞利用方面的有效性。
—The severity of information leak ( infoleak for short) in OS kernels cannot be underestimated, and various exploitation techniques have been proposed to achieve infoleak in OS kernels. Among them, memory-error-based infoleak is powerful and widely used in real-world exploits. However, existing approaches to finding memory-error-based infoleak lack the systematic reasoning about its search space, and do not fully explore the search space. Consequently, they fail to exploit a large number of memory errors in the kernel. According to a theoretical modeling of memory errors, the actual search space of such approach is huge, as multiple steps could be involved in the exploitation process, and virtually any memory error can be exploited to achieve infoleak. To bridge the gap between the theory and reality, we propose a framework K-LEAK to facilitate generating memory-error-based infoleak exploits in the Linux kernel. K-LEAK considers infoleak exploit generation as a data-flow search problem. By modeling unintended data flows introduced by memory errors, and how existing memory errors can create new memory errors, K-LEAK can systematically search for infoleak data-flow paths in a multi-step manner. We implement a prototype of K-LEAK and evaluate it with memory errors from syzbot and CVEs. The evaluation results demonstrate the effectiveness of K-LEAK in generating diverse infoleak exploits using various multi-step strategies.