Program-mandering: Quantitative Privilege Separation
Shen Liu, Dongrui Zeng, Yongzhe Huang, Frank Capobianco, Stephen McCamant, Trent Jaeger, Gang Tan
Abstract
Privilege separation is an effective technique to improve software security. However, past partitioning systems do not allow programmers to make quantitative tradeoffs between security and performance. In this paper, we describe our toolchain called PM. It can automatically find the optimal boundary in program partitioning. This is achieved by solving an integer-programming model that optimizes for a user-chosen metric while satisfying the remaining security and performance constraints on other metrics. We choose security metrics to reason about how well computed partitions enforce information flow control to: (1) protect the program from low-integrity inputs or (2) prevent leakage of program secrets. As a result, functions in the sensitive module that fall on the optimal partition boundaries automatically identify where declassification is necessary. We used PM to experiment on a set of real-world programs to protect confidentiality and integrity; results show that, with moderate user guidance, PM can find partitions that have better balance between security and performance than partitions found by a previous tool that requires manual declassification. CCS CONCEPTS • Security and privacy → Software and application security; • Software and its engineering → Automated static analysis; Dynamic analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 60afa74a-5612-4a33-8f78-9c321bb0ab04Cited by top-tier papers12
- DynPTA: Combining Static and Dynamic Analysis for Practical Selective Data ProtectionTapti Palit, Jarin Firose Moon, Fabian Monrose, Michalis PolychronakisS&P 2021 · 48 citations
- Annotating, Tracking, and Protecting Cryptographic Secrets with CryptoMPKXuancheng Jin, Xuangan Xiao, Songlin Jia, Wang Gao et al.S&P 2022 · 31 citations
- Preventing Dynamic Library Compromise on Node.js via RWX-Based Privilege ReductionNikos Vasilakis, Cristian-Alexandru Staicu, Grigoris Ntousakis, Konstantinos Kallas et al.CCS 2021 · 27 citations
- KSplit: Automating Device Driver IsolationYongzhe Huang, Vikram Narayanan, David Detweiler, Kaiming Huang et al.OSDI 2022 · 26 citations
- OPEC: operation-based security isolation for bare-metal embedded systemsXia Zhou, Jiaqi Li, Wenlong Zhang, Yajin Zhou et al.EuroSys 2022 · 18 citations
Builds on2
Related papers
- DeJITLeak: eliminating JIT-induced timing side-channel leaksQi Qin, JulianAndres JiYang, Fu Song, Taolue Chen et al.FSE 2022 · 18 citations
- Fast Flow-Sensitive C Program Partitioning via Iterative Value-Flow RefinementMaxwell Levatich, Stephen A. EdwardsICSE 2026
- Compositional Security Definitions for Higher-Order Where DeclassificationJan Menz, Andrew K. Hirsch, Peixuan Li, Deepak GargOOPSLA 2023 · 3 citations
- Helium: Quantifying Microarchitectural Side-Channel Leakage with Probabilistic GuaranteesSamantha Archer, Mohammad Rahmani Fadiheh, Caroline TrippelISCA 2026
- JVM fuzzing for JIT-induced side-channel detectionTegan Brennan, Seemanta Saha, Tevfik BultanICSE 2020 · 26 citations
