SysComb:用于缩减攻击面的细粒度透明系统调用过滤
SysComb: Fine-Grained Transparent System Call Filtering for Attack Surface Reduction
浏览论文内容
中文总结 AI 辅助
本文提出基于eBPF的SysComb方案,无需修改应用或内核即可实现细粒度透明系统调用过滤,支持两种策略,开销低且实用,可缩减攻击面并降低入侵影响。
中文摘要 AI 辅助
限制应用程序可使用的系统调用能缩减内核的攻击面,大幅降低被入侵程序造成的影响。现有生成系统调用过滤器的方法均需要修改内核或应用程序以在运行时激活,这具有侵入性、易出错且常不切实际,尤其当代码由外部方维护时。本文提出SysComb,一种基于eBPF的新型解决方案,可基于应用状态实施时间专用的系统调用过滤器,无需修改应用或内核代码,解决上述局限。此外,SysComb允许开发者选择两种不同的实施策略:类seccomp策略,确保状态转换后不获得新特权;最小权限策略,为每个状态应用最严格的过滤器。我们使用广泛应用的软件评估SysComb,展示其准确的状态感知系统调用过滤能力,且开销与内置内核解决方案相当,证明该方法的实用性。
英文摘要
Restricting the system calls available to applications shrinks the kernel's attack surface and greatly mitigates the impact of compromised programs. Recent approaches showcase techniques to generate system call filters, however, all existing solutions require either kernel or application modifications to activate them at runtime. This is intrusive, error-prone, and often impractical, especially when the code is maintained by external parties. This paper presents SysComb, a novel eBPF-based solution to enforce temporally-specialized system call filters based on the application state, without requiring any modification to the application or the kernel code, and thus addressing the above limitations. Moreover, SysComb lets the developer choose between two distinct enforcement strategies: seccomp-like, ensuring no new privileges are gained after a state transition is performed, and least-privilege, which applies to each state the most restrictive filter. We evaluated SysComb using widely used software, showcasing accurate state-aware system call filtering and an overhead comparable to built-in kernel solutions, demonstrating the practicality of our approach.