arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

通过二进制操作对整个Linux发行版进行信任-信任攻击

Trusting-Trust Attack against an Entire Linux Distribution through Binary Manipulation

Julien Malka, Aman Sharma, Martin Monperrus, Stefano Zacchiroli, Théo Zimmermann

arXiv 2607.24888首次发表:更新:

发表机构

Institut Polytechnique de Paris; KTH Royal Institute of Technology(巴黎理工学院; 瑞典皇家理工学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究针对Linux发行版的信任-信任攻击,利用对成品ELF文件的操作,围绕GNU strip构建攻击。在NixOS引导中植入有效载荷,在实际nixpkgs版本上成功构建安装程序并植入后门,证明该攻击不限于编译器。

AI 中文摘要

肯·汤普森的信任-信任攻击,即被攻破的编译器为其构建的程序植入后门,并在自身后续重建中重现该后门,通常被视为编译器特有的威胁。本文表明并非如此。我们围绕GNU strip构建了完整的信任-信任攻击,它是一个普通的构建工具,不检查也不生成源代码,仅通过对成品ELF文件的操作。在NixOS Linux发行版的引导过程中,二进制种子中一个被篡改的strip植入有效载荷,从一代strip传播到下一代,并在种子离开依赖闭包后存活到最终标准环境。在实际的nixpkgs版本上,攻击成功构建了完整的图形安装程序且几乎为其每个二进制文件植入后门,使被颠覆的包能够进行任意恶意行为。

英文摘要

Ken Thompson's trusting-trust attack, in which a compromised compiler backdoors the programs it builds and reproduces the backdoor in subsequent rebuilds of itself, is widely regarded as a threat specific to compilers. We show that it is not. We construct a complete trusting-trust attack around GNU strip, an ordinary build utility that neither inspects nor generates source code, using only manipulations of finished ELF files. In the bootstrap of the NixOS Linux distribution, a single tampered strip in the binary seed implants a payload that propagates from one generation of strip to the next and survives into the final standard environment after the seed leaves the dependency closure. On a real nixpkgs revision, the attack builds a complete graphical installer without failures and backdoors almost every one of its binaries, enabling arbitrary malicious behavior of the subverted packages.

DOI:10.1145/3848003.3848012

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑