Automatic Permission Check Analysis for Linux Kernel

Automatic Permission Check Analysis for Linux Kernel
复制标题

DOI:
10.1109/tdsc.2022.3165368
复制
发表时间:
2023-05
影响因子:
7.3
通讯作者:
Jinmeng Zhou;Tong Zhang;Wenbo Shen;Dongyoon Lee;Changhee Jung;Ahmed M. Azab;Ruowen Wang;P. Ning;K. Ren
Jinmeng Zhou;Tong Zhang;Wenbo Shen;Dongyoon Lee;Changhee Jung;Ahmed M. Azab;Ruowen Wang;P. Ning;K. Ren
中科院分区:
计算机科学2区
文献类型:
--
作者:
Jinmeng Zhou;Tong Zhang;Wenbo Shen;Dongyoon Lee;Changhee Jung;Ahmed M. Azab;Ruowen Wang;P. Ning;K. Ren

文献摘要

相似文献

权限检查通过提供对特权功能的访问控制,在操作系统安全性中起着至关重要的作用。然而,由于庞大的代码库和内核的复杂性,对于内核开发人员来说,以可伸缩性的方式验证现有检查的可靠性是一项挑战。事实上,Linux内核包含数百万行代码和数百个权限检查,更糟糕的是,它的复杂性正在快速增长。本文介绍了LinuX的静态权限检查错误检测器PeX,它将内核源代码作为输入,并报告任何缺失的、不一致的和冗余的权限检查。PeX使用KIRIN(基于内核接口的间接调用分析),这是一种新颖、精确、可扩展的间接调用分析技术。通过KIRIN构建的过程间控制流图,PeX自动识别权限检查,并推断权限检查与特权功能之间的映射关系。对于每个特权函数,PeX检查到该函数的所有可能路径,以检查是否正确执行了必要的权限检查。我们在最新稳定的Linux内核v4.18.5上对PeX进行了三种类型的权限检查评估:自主访问控制(Discretionary Access Controls, DAC)、功能和Linux安全模块(Linux Security Modules, LSM)。PeX报告了45个新的权限检查错误,其中17个已经被内核开发人员确认。
Permission checks play an essential role in operating system security by providing access control to privileged functionalities. However, it is challenging for kernel developers to scalably verify the soundness of existing checks due to the large codebase and complexity of the kernel. In fact, Linux kernel contains millions of lines of code with hundreds of permission checks, and even worse, its complexity is fast-growing. This paper presents PeX, a static Permission check error detector for LinuX, which takes as input a kernel source code and reports any missing, inconsistent, and redundant permission checks. PeX uses KIRIN (Kernel InteRface based Indirect call aNalysis), a novel, precise, and scalable indirect call analysis technique. Over the interprocedural control flow graph built by KIRIN, PeX automatically identifies permission checks and infers the mappings between permission checks and privileged functions. For each privileged function, PeX examines all possible paths to the function to check if necessary permission checks are correctly enforced. We evaluated PeX on the latest stable Linux kernel v4.18.5 for three types of permission checks: Discretionary Access Controls (DAC), Capabilities, and Linux Security Modules (LSM). PeX reported 45 new permission check errors, 17 of which have been confirmed by the kernel developers.