SysXCHG: Refining Privilege with Adaptive System Call Filters
Alexander J. Gaidis, Vaggelis Atlidakis, Vasileios P. Kemerlis
Abstract
We present the design, implementation, and evaluation of SysXCHG: a system call (syscall) filtering enforcement mechanism that enables programs to run in accordance with the principle of least privilege. In contrast to the current, hierarchical design of seccomp-BPF, which does not allow a program to run with a different set of allowed syscalls than its descendants, SysXCHG enables applications to run with "tight" syscall filters, uninfluenced by any future-executed (sub-)programs, by allowing filters to be dynamically exchanged at runtime during execve[at]. As a part of SysXCHG, we also present xfilter: a mechanism for fast filtering using a process-specific view of the kernel's syscall table where filtering is performed. In our evaluation of SysXCHG, we found that our filter exchanging design is performant, incurring ≤= 1.71% slowdown on real-world programs in the PaSH benchmark suite, as well as effective, blocking vast amounts of extraneous functionality, including security-critical syscalls, which the current design of seccomp-BPF is unable to.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 94e10540-4da6-4c2c-a372-4c3fdf114ae0Cited by top-tier papers2
- BeeBox: Hardening BPF against Transient Execution AttacksDi Jin, Alexander J. Gaidis, Vasileios P. KemerlisUSENIX Security 2024 · 10 citations
- Controlling Opaque-Component Effects with Semisolates and TryEvangelos Lamprou, Tianyu (Ezri) Zhu, Di Jin, Grigoris Ntousakis et al.OSDI 2026 · 4 citations
Builds on14
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp et al.USENIX Security 2019 · 442 citations
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- Debloating Software through Piece-Wise Compilation and LoadingAnh Quach, Aravind Prakash, Lok-Kwong YanUSENIX Security 2018 · 153 citations
- Block Oriented Programming: Automating Data-Only AttacksKyriakos K. Ispoglou, Bader AlBassam, Trent Jaeger, Mathias PayerCCS 2018 · 143 citations
- RAZOR: A Framework for Post-deployment Software DebloatingChenxiong Qian, Hong Hu, Mansour Alharthi, Simon Pak Ho Chung et al.USENIX Security 2019 · 132 citations
Related papers
- Automated policy synthesis for system call sandboxingShankara Pailoor, Xinyu Wang, Hovav Shacham, Isil DilligOOPSLA 2020 · 23 citations
- Protect the System Call, Protect (Most of) the World with BASTIONChristopher Jelesnianski, Mohannad Ismail, Yeongjin Jang, Dan Williams et al.ASPLOS 2023 · 15 citations
- Jenny: Securing Syscalls for PKU-based Memory Isolation SystemsDavid Schrammel, Samuel Weiser, Richard Sadek, Stefan MangardUSENIX Security 2022
- Draco: Architectural and Operating System Support for System Call SecurityDimitrios Skarlatos, Qingrong Chen, Jianyan Chen, Tianyin Xu et al.MICRO 2020 · 17 citations
- Applying System Call Filtering to Real-World Binaries (Experience Paper)Soumyakant Priyadarshan, Seyedhamed GhavamniaISSTA 2026 · 1 citation
