1
Return

Vaccine: Injection Vulnerabilities Mitigation through Dynamic Process Control with eBPF

delete2025-11-27
delete0
PRE
AI
H
Hanyu Wang
A
Aimin Yu
L
Lifang Xiao
L
Lixin Zhao
X
Xu Cao
D
Dan Meng
DOI:10.1016/j.cose.2025.104788delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Injection vulnerabilities are becoming increasingly prevalent and pose a significant threat to system security. A great deal of work highly depends on the patches for defense against these vulnerabilities. However, there is often a delay between the discovery of the vulnerabilities and the release of the corresponding patches, which leaves systems exposed to potential attacks. To address this issue, it is essential to build a vulnerability-tolerant mechanism that aims to inhibit the execution of injected payloads even when vulnerabilities are exploited. Our insight is that most of the injection vulnerabilities in operating systems can be mitigated through dynamic process control, inhibiting their ability to execute attacks. Based on this observation, we present Vaccine, a method for mitigating injection vulnerabilities by restricting attacks through dynamic process control using eBPF. Vaccine leverages process-level behavioral deviations to determine process permissions for control. By dynamically modifying process memory space to modify process permissions, Vaccine restricts the execution of injected payloads, effectively preventing attacks dynamically, hence mitigating injection vulnerabilities. The experimental results indicate that the Vaccine mitigates injection attacks exploiting 40 injection vulnerabilities. We demonstrate the behavioral deviations between processes to prove the feasibility of process-based permission control. Notably, Vaccine reduces the impact on benign behaviors by 32% to 78% than an advanced tool through fine-grained and dynamic control. Furthermore, it incurs low latency loss and overhead compared to three behavioral analysis methods. These results further demonstrate its practical defense against injection vulnerabilities.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

No organization information available
Cited Papers

Cited Papers

Citing Papers

Citing Papers