Saphire: Sandboxing PHP Applications with Tailored System Call Allowlists
Alexander Bulekov, Rasoul Jahanshahi, Manuel Egele
摘要
Interpreted languages, such as PHP, power a host of platformindependent applications, including websites, instant messengers, video games, and development environments. With the flourishing popularity of these applications, attackers have honed in on finding and exploiting vulnerabilities in interpreted code. Generally, all parts of an interpreted application execute with uniform and superfluous privileges, increasing the potential damage from an exploit. This lack of privilegeseparation is in stark violation of the principle of least privilege(PoLP). Despite 1,980 web app remote code execution (RCE) vulnerabilities discovered in 2018 alone [25] , current defenses rely on incomplete detection of vulnerable code, or extensive collections of benign inputs. Considering the limitations of bug-finding systems, the violation of the PoLP exposes systems to unnecessarily-high risks. In this paper, we identify the current challenges with applying the PoLP to interpreted PHP applications, and propose a novel generic approach for automatically deriving system-call policies for individual interpreted programs. This effectively reduces the attack surface (i.e., set of system-calls) an exploit can leverage to the system-calls the script needs to perform its benign functionality. We name our implementation of this approach, Saphire, and thoroughly evaluate the prototype with respect to its security and performance characteristics. Our evaluation on 21 known vulnerable web apps and plugins shows that Saphire successfully prevents RCE exploits, and is able to do so with negligible performance overhead (i.e., <2% in the worst case) for real-world web apps. Saphire performs its service without causing false positives over automatically and manually generated benign traffic to each web app.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- TChecker: Precise Static Inter-Procedural Analysis for Detecting Taint-Style Vulnerabilities in PHP ApplicationsChanghua Luo, Penghui Li, Wei MengCCS 2022 · 被引用 27 次
- SysXCHG: Refining Privilege with Adaptive System Call FiltersAlexander J. Gaidis, Vaggelis Atlidakis, Vasileios P. KemerlisCCS 2023 · 被引用 9 次
- Loupe: Driving the Development of OS Compatibility LayersHugo Lefeuvre, Gaulthier Gain, Vlad-Andrei Badoiu, Daniel Dinca 等ASPLOS 2024 · 被引用 7 次
- HODOR: Shrinking Attack Surface on Node.js via System Call LimitationWenya Wang, Xingwei Lin, Jingyi Wang, Wang Gao 等CCS 2023 · 被引用 3 次
- Argus: All your (PHP) Injection-sinks are belong to usRasoul Jahanshahi, Manuel EgeleUSENIX Security 2024 · 被引用 1 次
它引用的顶会 Paper1
相关 Paper
- Minimalist: Semi-automated Debloating of PHP Web Applications through Static AnalysisRasoul Jahanshahi, Babak Amin Azad, Nick Nikiforakis, Manuel EgeleUSENIX Security 2023
- Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter AnalysisPenghui Li, Wei Meng, Mingxue Zhang, Chenlin Wang 等S&P 2024 · 被引用 6 次
- On the Feasibility of Automated Built-in Function Modeling for PHP Symbolic ExecutionPenghui Li, Wei Meng, Kangjie Lu, Changhua LuoWWW 2021 · 被引用 18 次
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars 等USENIX Security 2024 · 被引用 45 次
- QUACK: Hindering Deserialization Attacks via Static Duck TypingYaniv David, Neophytos Christou, Andreas D. Kellas, Vasileios P. Kemerlis 等NDSS 2024
