arrow
Return

PrivGuard: Protecting Sensitive Kernel Data From Privilege Escalation Attacks

delete2018-01-01
delete14
delete
OA
AI
羌
羌卫中 (Weizhong Qiang) *
J
Jiawei Yang
金
金海 (Hai Jin)
X
Xuanhua Shi
DOI:10.1109/ACCESS.2018.2866498delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Kernels of operating systems are written in low-level unsafe languages, which make them inevitably vulnerable to memory corruption attacks. Most existing kernel defense mechanisms focus on preventing control-data attacks. Recently, attackers have turned the direction to non-control-data attacks by hijacking data flow, so as to bypass current defense mechanisms. Previous work has proved that non-control-data attacks are the critical threat to kernels. One of the important purposes of these attacks is to achieve privilege escalation by overwriting sensitive kernel data. The goal of our research is to develop a lightweight protection mechanism to mitigate non-control-data attacks that compromise sensitive kernel data. We propose an approach that enforces data integrity of sensitive kernel data by preventing the illegal write to these data to mitigate privilege escalation attacks. The main challenge of the proposed approach is to validate the modification of sensitive kernel data at runtime. The validation routine must verify the legitimacy of the duplicated sensitive data and ensure the credibility of the verification. To address this challenge, we modify the system call entry point to monitor the change of the sensitive kernel data without any change to Linux access control mechanism. Then, we use stack canaries to protect the duplication of sensitive kernel data that are used for integrity checking. In addition, we protect the integrity of sensitive kernel data by forbidding illegal updates to them. We have implemented the prototype for Linux kernel on Ubuntu Linux platform. The evaluation results of our prototype demonstrate that it can mitigate privilege escalation attacks and its performance overhead is moderate.
Keywords:
Kernel
non-control-data
credential
privilege escalation
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

No organization information available
Cited Papers

Cited Papers

Progress in the Development of Inhibitors of SH2 Domains
err2000-01-01
err0
PREAI
errWayne Cody; Zhiwu Lin; Robert Panek; David Rose; John Rubin
errShare
errSave
Functioning of intertidal flats inferred from temporal and spatial dynamics of O2, H2S and pH in their surface sediment
err2009-01-30
err0
errOAAI
errStefan Jansen; Eva Walpersdorf; Ursula Werner; Markus Billerbeck; Michael E Böttcher; Dirk de Beer
errShare
errSave
Effects of Elevated Peroxidase Levels and Corn Earworm Feeding on Gene Expression in Tomato
err2012-11-08
err0
PREAI
errHideaki Suzuki; Patrick F. Dowd; Eric T. Johnson; Sue M. Hum-Musser; Richard O. Musser
errShare
errSave
Hierarchical Morphology-Guided Tooth Instance Segmentation from CBCT Images
err2021-06-14
err0
PREAI
errZhiming Cui; Bojun Zhang; Chunfeng Lian; Changjian Li; Lei Yang; Wenping Wang; Min Zhu; Dinggang Shen
errShare
errSave
Accurate and efficient exploit capture and classification
err2016-09-13
err6
PREAI
errDing, Yu; Wei, Tao; Xue, Hui; Zhang, Yulong; Zhang, Chao; Han, Xinhui
errShare
errSave
researcher View more