LinkGuard: A Lightweight State-Aware Runtime Guard Against Link Following Attacks in Windows File System
Bocheng Xiang, Yuan Zhang, Hao Huang, Fengyu Liu, Youkun Shi
Abstract
—Link Following (LF) attacks in the Windows file sys-tem allow adversaries to stealthily redirect benign file operations to protected files by abusing crafted combinations of symbolic links (link chains), thereby enabling arbitrary manipulation of protected files. Such attacks typically manifest as either single-step attacks or multi-step attacks, depending on the sequencing of the constructed link chain. Existing countermeasures against LF attacks either rely on heavyweight modeling or suffer from poor compatibility and limited applicability, and none provide comprehensive protection across different types of LF attacks. In this paper, we present LinkGuard , a lightweight state-aware runtime guard against LF attacks targeting Windows systems. The novelty of LinkGuard lies in its two-stage design: The first stage aims to improve defense efficiency by performing dynamic subject filtering, which monitors only file operations and associated subjects involved in the creation and following of link chains; The second stage applies FSM-based rule matching to precisely defend LF attacks, ensuring effective and accurate defense. We evaluate LinkGuard ’s prototype across five representative Windows systems to validate its compatibility. On a dataset of 70 real-world vulnerabilities, LinkGuard successfully mitigates all single-step attacks and 95.45% of multi-step attacks, with zero false positives on benign operations. On average, LinkGuard only incurs 1% overhead in microbenchmarks and 3.4% overhead in real-world application workloads, while adding a negligible 5 ms latency on benign file operations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 407ef9d9-7dcf-4f45-8c06-251c829770c1Builds on3
- Unveiling BYOVD Threats: Malware's Use and Abuse of Kernel DriversAndrea Monzani, Antonio Parata, Andrea Oliveri, Simone Aonzo et al.NDSS 2026 · 5 citations
- Pig in a Poke: Automatically Detecting and Exploiting Link Following Vulnerabilities in Windows File OperationsBocheng Xiang, Yuan Zhang, Fengyu Liu, Hao Huang et al.USENIX Security 2025
- File Hijacking Vulnerability: The Elephant in the RoomChendong Yu, Yang Xiao, Jie Lu, Yuekang Li et al.NDSS 2024
Related papers
- Mew: Enabling Large-Scale and Dynamic Link-Flooding Defenses on Programmable SwitchesHuancheng Zhou, Sungmin Hong, Yangyang Liu, Xiapu Luo et al.S&P 2023
- FreeGuard: A Faster Secure Heap AllocatorSam Silvestro, Hongyu Liu, Corey Crosser, Zhiqiang Lin et al.CCS 2017 · 71 citations
- Windows plays Jenga: Uncovering Design Weaknesses in Windows File System SecurityDong-uk Kim, JunYoung Park, Sanghak Oh, Hyoungshick Kim et al.CCS 2025
- DMGuard: Safeguarding Kernels from Physical-Page Use-After-Free VulnerabilitiesJuhee Kim, Jaeyoung Chung, Dae R. Jeong, Byoungyoung LeeUSENIX Security 2026
- BlueSWAT: A Lightweight State-Aware Security Framework for Bluetooth Low EnergyXijia Che, Yi He, Xuewei Feng, Kun Sun et al.CCS 2024 · 10 citations
