Building Dynamic System Call Sandbox with Partial Order Analysis
Quan Zhang, Chijin Zhou, Yiwen Xu, Zijing Yin, Mingzhe Wang, Zhuo Su, Chengnian Sun, Yu Jiang, Jia-Guang Sun
摘要
Attack surface reduction is a security technique that secures the operating system by removing the unnecessary code or features of a program. By restricting the system calls that programs can use, the system call sandbox is able to reduce the exposed attack surface of the operating system and prevent attackers from damaging it through vulnerable programs. Ideally, programs should only retain access to system calls they require for normal execution. Many researchers focus on adopting static analysis to automatically restrict the system calls for each program. However, these methods do not adjust the restriction policy along with program execution. Thus, they need to permit all system calls required for program functionalities.
We observe that some system calls, especially security-sensitive ones, are used a few times in certain stages of a program's execution and then never used again. This motivates us to minimize the set of required system calls dynamically. In this paper, we propose DynBox, which gradually disables access to unnecessary system calls throughout the program's execution. To accomplish this, we utilize partial order analysis to transform the program into a partially ordered graph, which enables efficient identification of the necessary system calls at any given point during program execution. Once a system call is no longer required by the program, DynBox can restrict it immediately. To evaluate DynBox, we applied it to seven widely-used programs with an average of 615 KLOC, including web servers and databases. With partial order analysis, DynBox restricts an average of 23.50, 16.86, and 15.89 more system calls than the state-of-the-art Chestnut, Temporal Specialization, and the configuration-aware sandbox, C2C, respectively. For mitigating malicious exploitations, on average, DynBox defeats 83.42% of 1726 exploitation payloads with only a 5.07% overhead.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Imperceptible Content Poisoning in LLM-Powered ApplicationsQuan Zhang, Chijin Zhou, Gwihwan Go, Binqi Zeng 等ASE 2024 · 被引用 3 次
- Janus: Detecting Rendering Bugs in Web Browsers via Visual Delta ConsistencyChijin Zhou, Quan Zhang, Bingzhou Qian, Yu JiangICSE 2025 · 被引用 2 次
它引用的顶会 Paper11
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- Debloating Software through Piece-Wise Compilation and LoadingAnh Quach, Aravind Prakash, Lok-Kwong YanUSENIX Security 2018 · 被引用 153 次
- Site Isolation: Process Separation for Web Sites within the BrowserCharles Reis, Alexander Moshchuk, Nasko OskovUSENIX Security 2019 · 被引用 105 次
- AdvDoor: adversarial backdoor attack of deep learning systemQuan Zhang, Yifeng Ding, Yongqiang Tian, Jianmin Guo 等ISSTA 2021 · 被引用 57 次
- Automated policy synthesis for system call sandboxingShankara Pailoor, Xinyu Wang, Hovav Shacham, Isil DilligOOPSLA 2020 · 被引用 23 次
相关 Paper
- Temporal System Call Specialization for Attack Surface ReductionSeyedhamed Ghavamnia, Tapti Palit, Shachee Mishra, Michalis PolychronakisUSENIX Security 2020
- C2C: Fine-grained Configuration-driven System Call FilteringSeyedhamed Ghavamnia, Tapti Palit, Michalis PolychronakisCCS 2022 · 被引用 22 次
- SysPart: Automated Temporal System Call Filtering for BinariesVidya Lakshmi Rajagopalan, Konstantinos Kleftogiorgos, Enes Göktas, Jun Xu 等CCS 2023 · 被引用 10 次
- Privbox: Faster System Calls Through Sandboxed Privileged ExecutionDmitry Kuznetsov, Adam MorrisonUSENIX ATC 2022 · 被引用 10 次
- AMPLE: Fine-grained File Access Policies for Server ApplicationsSeyedhamed Ghavamnia, Julien VanegueASE 2025
