• DocumentCode
    3392547
  • Title

    Automatic extraction of accurate application-specific sandboxing policy

  • Author

    Lam, Lap-chung ; Chiueh, Tzi-cker

  • Author_Institution
    Rether Networks, Inc., NY
  • fYear
    2005
  • fDate
    17-20 Oct. 2005
  • Firstpage
    713
  • Abstract
    One of the most dangerous cybersecurity threats is control hijacking attacks, which hijack the control of a victim application, and execute arbitrary system calls assuming the identity of the victim program´s effective user. System call monitoring has been touted as an effective defense against control hijacking attacks because it could prevent remote attackers from inflicting damage upon a victim system even if they can successfully compromise certain applications running on the system. However, the Achilles´ heel of the system call monitoring approach is the construction of accurate system call behavior model that minimizes false positives and negatives. This paper describes the design, implementation, and evaluation of a program semantics-aware intrusion detection system called Paid, which automatically derives an application-specific system call behavior model from the application´s source code, and checks the application´s run-time system call pattern against this model to thwart any control hijacking attacks. Experiments on a fully working Paid prototype show that Paid can indeed stop attacks that exploit non-standard security holes, such as format string attacks that modify function pointers, and that the run-time latency and throughput penalty of Paid are under 11.66% and 10.44%, respectively, for a set of production-mode network server applications including Apache, Sendmail, Ftp daemon, etc
  • Keywords
    Internet; security of data; source coding; telecommunication security; accurate application-specific sandboxing policy; cybersecurity threats; hijacking attacks; production-mode network server; program semantics-aware intrusion detection system; source code; system call monitoring; Automatic control; Computer security; Control systems; Delay; Intrusion detection; Network servers; Prototypes; Remote monitoring; Runtime; Throughput;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Military Communications Conference, 2005. MILCOM 2005. IEEE
  • Conference_Location
    Atlantic City, NJ
  • Print_ISBN
    0-7803-9393-7
  • Type

    conf

  • DOI
    10.1109/MILCOM.2005.1605766
  • Filename
    1605766