TALISMAN: Tamper Analysis for Reference Monitors
Frank Capobianco, Quan Zhou, Aditya Basu, Trent Jaeger, Danfeng Zhang
摘要
—Correct access control enforcement is a critical foundation for data security. The reference monitor is the key component for enforcing access control, which is supposed to provide tamperproof mediation of all security-sensitive operations. Since reference monitors are often deployed in complex software handling a wide variety of operation requests, such as operating systems and server programs, a question is whether reference monitor implementations may have flaws that prevent them from achieving these requirements. In the past, automated analyses detected flaws in complete mediation. However, researchers have not yet developed methods to detect flaws that may tamper with the reference monitor, despite the many vulnerabilities found in such programs. In this paper, we develop T ALISMAN , an automated analysis for detecting flaws that may tamper the execution of reference monitor implementations. At its core, T ALISMAN implements a precise information flow integrity analysis to detect violations that may tamper the construction of authorization queries. T ALISMAN applies a new, relaxed variant of noninterference that eliminates several spurious implicit flow violations. T ALISMAN also provides a means to vet expected uses of untrusted data in authorization using endorsement. We apply T ALISMAN on three reference monitor implementations used in the Linux Security Modules framework, SELinux, AppArmor, and Tomoyo, verifying 80% of the arguments in authorization queries generated by these LSMs. Using T ALISMAN , we also found vulnerabilities in how pathnames are used in authorization by Tomoyo and AppArmor allowing adversaries to circumvent authorization. T ALISMAN shows that tamper analysis of reference monitor implementations can automatically verify many cases and also enable the detection of critical flaws.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper6
- Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints InferencesKangjie Lu, Aditya Pakki, Qiushi WuUSENIX Security 2019 · 被引用 97 次
- PtrSplit: Supporting General Pointers in Automatic Program PartitioningShen Liu, Gang Tan, Trent JaegerCCS 2017 · 被引用 83 次
- Nonmalleable Information Flow ControlEthan Cecchetti, Andrew C. Myers, Owen ArdenCCS 2017 · 被引用 49 次
- KSplit: Automating Device Driver IsolationYongzhe Huang, Vikram Narayanan, David Detweiler, Kaiming Huang 等OSDI 2022 · 被引用 26 次
- Detecting Missed Security Operations Through Differential Checking of Object-based Similar PathsDinghao Liu, Qiushi Wu, Shouling Ji, Kangjie Lu 等CCS 2021 · 被引用 11 次
相关 Paper
- Tainted Secure Multi-Execution to Restrict Attacker InfluenceMcKenna McCall, Abhishek Bichhawat, Limin JiaCCS 2023 · 被引用 1 次
- PeX: A Permission Check Analysis Framework for Linux KernelTong Zhang, Wenbo Shen, Dongyoon Lee, Changhee Jung 等USENIX Security 2019 · 被引用 77 次
- AceDroid: Normalizing Diverse Android Access Control Checks for Inconsistency DetectionYousra Aafer, Jianjun Huang, Yi Sun, Xiangyu Zhang 等NDSS 2018 · 被引用 95 次
- Protect the System Call, Protect (Most of) the World with BASTIONChristopher Jelesnianski, Mohannad Ismail, Yeongjin Jang, Dan Williams 等ASPLOS 2023 · 被引用 15 次
- Finding Cracks in Shields: On the Security of Control Flow Integrity MechanismsYuan Li, Mingzhe Wang, Chao Zhang, Xingman Chen 等CCS 2020 · 被引用 32 次
