USENIX Security2024Top-tier venue
ChainReactor: Automated Privilege Escalation Chain Discovery via AI Planning
Giulio De Pasquale, Ilya Grishchenko, Riccardo Iesari, Gabriel Pizarro, Lorenzo Cavallaro, Christopher Kruegel, Giovanni Vigna
Abstract
Current academic vulnerability research predominantly focuses on identifying individual bugs and exploits in programs and systems. However, this goes against the growing trend of modern, advanced attacks that rely on a sequence of steps (i.e., a chain of exploits) to achieve their goals, often incorporating individually benign actions. This paper introduces a novel approach to the automated discovery of such exploitation chains using AI planning. In particular, we aim to discover privilege escalation chains, some of the most critical and pervasive security threats, which involve exploiting vulnerabilities to gain unauthorized access and control over systems. We implement our approach as a tool, ChainReactor, that models the problem as a sequence of actions to achieve privilege escalation from the initial access to a target system. ChainReactor extracts information about available executables, system configurations, and known vulnerabilities on the target and encodes this data into a Planning Domain Definition Language (PDDL) problem. Using a modern planner, ChainReactor can generate chains incorporating vulnerabilities and benign actions. We evaluated ChainReactor on 3 synthetic vulnerable VMs, 504 real-world Amazon EC2 and 177 Digital Ocean instances, demonstrating its capacity to rediscover known privilege escalation exploits and identify new chains previously unreported. Specifically, the evaluation showed that ChainReactor successfully rediscovered the exploit chains in the Capture the Flag (CTF) machines and identified zero-day chains on 16 Amazon EC2 and 4 Digital Ocean VMs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 94147fd5-755f-40d2-81bb-7ef283d8bfe0Cited by top-tier papers2
- From Assistance to Autonomy: An Empirical Study of AI Use in a Live Capture-the-Flag (CTF) CompetitionTingxuan Tang, Nicolas Janis, Kalyn Asher Montague, Kevin Eykholt et al.USENIX Security 2026
- PrivEscalate: Measuring and Augmenting the Threat of LLM-Automated Linux Privilege EscalationYixuan Liu, Zilong Zhen, Yin Wu, Yi LiCCS 2026
Builds on6
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Attacks on Wireless Coexistence: Exploiting Cross-Technology Performance Features for Inter-Chip Privilege EscalationJiska Classen, Francesco Gringoli, Michael Hermann, Matthias HollickS&P 2022 · 16 citations
- Finding SMM Privilege-Escalation Vulnerabilities in UEFI Firmware with Protocol-Centric Static AnalysisJiawei Yin, Menghao Li, Wei Wu, Dandan Sun et al.S&P 2022 · 15 citations
- Horizontal Privilege Escalation in Trusted ApplicationsDarius Suciu, Stephen E. McLaughlin, Laurent Simon, Radu SionUSENIX Security 2020
- Extending a Hand to Attackers: Browser Privilege Escalation Attacks via ExtensionsYoung Min Kim, Byoungyoung LeeUSENIX Security 2023
Related papers
- GadgetHunter: Region-Based Neuro-symbolic Detection of Java Deserialization VulnerabilitiesKaixuan Li, Jian Zhang, Chong Wang, Sen Chen et al.FSE 2026
- Nothing is Unreachable: Automated Synthesis of Robust Code-Reuse Gadget Chains for Arbitrary Exploitation PrimitivesNicolas Bailluet, Emmanuel Fleury, Isabelle Puaut, Erven RohouUSENIX Security 2025
- The Dark Side of Flexibility: Detecting Risky Permission Chaining Attacks in Serverless ApplicationsXunqi Liu, Nanzi Yang, Chang Li, Jinku Li et al.NDSS 2026 · 1 citation
- Chainsaw: Chained Automated Workflow-based Exploit GenerationAbeer Alhuzali, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2016 · 52 citations
- GVI: Guided Vulnerability Imagination for Boosting Deep Vulnerability DetectorsHeng Yong, Zhong Li, Minxue Pan, Tian Zhang et al.ICSE 2025 · 2 citations
