arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.29979cs.CRcs.NI

打破环境信任:针对横向移动的网络内每进程访问控制

Breaking Ambient Trust: In-Network Per-Process Access Control Against Lateral Movement

Osama Bajaber, Bo Ji, Peng Gao

首次发表
浏览论文内容

中文总结 AI 辅助

针对企业网络中APT攻击的横向移动问题,提出NetZone网络内访问控制机制,通过绑定用户进程的AccessScope实现进程级访问管控,可防御复杂攻击且开销可忽略。

中文摘要 AI 辅助

企业网络仍易受高级持续威胁(APTs)攻击,攻击者先获得初始立足点,再在网络中横向移动,逐跳累积访问权限以抵达关键目标。现有网络防御无法跨网络跟踪进程级别的用户移动,而是对主机内所有进程赋予环境信任。因此,一旦主机被攻陷,恶意进程会继承受害者的权限,从而扩大攻击者的访问范围并实现进一步的横向移动。为解决这一缺口,我们提出NetZone,一种网络内访问控制机制,可将每个用户进程限制在固定的访问范围内,该范围在用户跨网络移动时保持不变。NetZone引入了名为AccessScope的新抽象,代表绑定到用户进程的轻量级访问能力。每个AccessScope编码了用户身份被授权访问的主机集合,并嵌入在进程的出站网络流量中,在到达目的地前进行验证。当用户在主机间切换时,AccessScope会随其流量传播,重新绑定到接收进程,并在主机间保持持久化。这确保无论网络位置如何,用户进程始终受其绑定的AccessScope管控,且访问权限保持不变。为处理进程产生的大量网络流量,我们开发了将可编程交换机与eBPF集成的数据平面协同设计。NetZone采用一系列网络内优化和轻量级AccessScope持久化技术,实时检查嵌入的AccessScope,实现高流量下的线速处理,且延迟开销可忽略不计。我们的广泛评估表明,NetZone可有效防御复杂攻击场景,且不会引入明显的开销。

英文摘要

Enterprise networks remain vulnerable to Advanced Persistent Threats (APTs), where adversaries gain an initial foothold and move laterally across the network, accumulating access permissions hop by hop to reach critical targets. Existing network defenses cannot track user movement at the process level across the network; instead, they grant ambient trust to all processes within a host. As a result, once a host is compromised, malicious processes inherit the victim's permissions, thereby expanding the attacker's access scope and enabling further lateral movement. To address this gap, we present NetZone, an in-network access control that confines each user process to a fixed access scope that persists as the user moves across the network. NetZone introduces a new abstraction, called AccessScope, which represents a lightweight access capability bound to the user's processes. Each AccessScope encodes the set of hosts a user identity is authorized to access and is embedded in the process's outgoing network traffic for validation before reaching its destination. As users pivot across hosts, AccessScope propagates with their traffic, rebinds to the receiving process, and persists across hosts. This ensures that regardless of network location, the user's processes are consistently governed by their bound AccessScope and their access permissions remain unchanged. To handle the high volume of network traffic generated by processes, we develop a data-plane co-design that integrates programmable switches with eBPF. NetZone employs a set of in-network optimizations and lightweight AccessScope persistence techniques to inspect the embedded AccessScope on the fly, enabling line-rate processing of high traffic volumes with negligible latency overhead. Our extensive evaluations show that NetZone can effectively defend against sophisticated attack scenarios without introducing noticeable overhead.

发表机构

  • King Abdulaziz University(阿卜杜勒阿齐兹国王大学)
  • Virginia Tech(弗吉尼亚理工大学)

机构由 AI 辅助整理,请以论文原文为准。

↑