C2C: Fine-grained Configuration-driven System Call Filtering
Seyedhamed Ghavamnia, Tapti Palit, Michalis Polychronakis
Abstract
Configuration options allow users to customize application features according to the desired requirements. While the code that corresponds to disabled features is never executed, it still resides in process memory and comprises part of the application's attack surface, e.g., it can be reused for the construction of exploit code. Automatically reducing the attack surface of disabled application features according to a given configuration is thus a desirable defense-indepth capability. The intricacies of modern software design and the complexities of popular programming languages, however, introduce significant challenges in automatically deriving the mapping of configuration options to their corresponding application code. In this paper, we present Configuration-to-Code (C2C), a generic configuration-driven attack surface reduction technique that automatically maps configuration options to application code using static code analysis and instrumentation. C2C operates at a fine-grained level by pruning configuration-dependent conditional branches in the control flow graph, allowing the precise identification of a given configuration option's code at the basic block level. At runtime, C2C reduces the application's attack surface by filtering any system calls required exclusively by disabled features. Using popular applications, we show how security-critical system calls (such as execve) can be automatically disabled when not needed, limiting an attacker's vulnerability exploitation capabilities. System call filtering also reduces the exposed attack surface of the underlying Linux kernel, neutralizing 32 additional CVEs (for a total of 88) compared to previous software specialization techniques. CCS CONCEPTS • Security and privacy → Software and application security; Operating systems security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f7a8f495-92d5-4a33-91c7-24ffcaf7bd24Cited by top-tier papers6
- Practical Data-Only Attack GenerationBrian Johannesmeyer, Asia Slowinska, Herbert Bos, Cristiano GiuffridaUSENIX Security 2024 · 16 citations
- Building Dynamic System Call Sandbox with Partial Order AnalysisQuan Zhang, Chijin Zhou, Yiwen Xu, Zijing Yin et al.OOPSLA 2023 · 5 citations
- Kaleidoscope: Precise Invariant-Guided Pointer AnalysisTapti Palit, Pedro FonsecaASPLOS 2024 · 3 citations
- Phoenix: Surviving Unpatched Vulnerabilities via Accurate and Efficient Filtering of Syscall SequencesHugo Kermabon-Bobinnec, Yosr Jarraya, Lingyu Wang, Suryadipta Majumdar et al.NDSS 2024
- PET: Prevent Discovered Errors from Being Triggered in the Linux KernelZicheng Wang, Yueqi Chen, Qingkai ZengUSENIX Security 2023
Builds on11
- Effective Program Debloating via Reinforcement LearningKihong Heo, Woosuk Lee, Pardis Pashakhanloo, Mayur NaikCCS 2018 · 175 citations
- Debloating Software through Piece-Wise Compilation and LoadingAnh Quach, Aravind Prakash, Lok-Kwong YanUSENIX Security 2018 · 153 citations
- RAZOR: A Framework for Post-deployment Software DebloatingChenxiong Qian, Hong Hu, Mansour Alharthi, Simon Pak Ho Chung et al.USENIX Security 2019 · 132 citations
- Less is More: Quantifying the Security Benefits of Debloating Web ApplicationsBabak Amin Azad, Pierre Laperdrix, Nick NikiforakisUSENIX Security 2019 · 100 citations
- SHARD: Fine-Grained Kernel Specialization with Context-Aware HardeningMuhammad Abubakar, Adil Ahmad, Pedro Fonseca, Dongyan XuUSENIX Security 2021 · 47 citations
Related papers
- Temporal System Call Specialization for Attack Surface ReductionSeyedhamed Ghavamnia, Tapti Palit, Shachee Mishra, Michalis PolychronakisUSENIX Security 2020
- Binary Control-Flow TrimmingMasoud Ghaffarinia, Kevin W. HamlenCCS 2019 · 42 citations
- SysPart: Automated Temporal System Call Filtering for BinariesVidya Lakshmi Rajagopalan, Konstantinos Kleftogiorgos, Enes Göktas, Jun Xu et al.CCS 2023 · 10 citations
- Going Native: Using a Large-Scale Analysis of Android Apps to Create a Practical Native-Code Sandboxing PolicyVitor Monte Afonso, Paulo L. de Geus, Antonio Bianchi, Yanick Fratantonio et al.NDSS 2016 · 119 citations
- Applying System Call Filtering to Real-World Binaries (Experience Paper)Soumyakant Priyadarshan, Seyedhamed GhavamniaISSTA 2026 · 1 citation
