DocumentCode :
580256
Title :
A Rose by Any Other Name or an Insane Root? Adventures in Name Resolution
Author :
Vijayakumar, Hayawardh ; Schiffman, Joshua ; Jaeger, Trent
Author_Institution :
Dept. of Comput. Sci. & Eng., Pennsylvania State Univ., University Park, PA, USA
fYear :
2011
fDate :
6-7 Sept. 2011
Firstpage :
1
Lastpage :
8
Abstract :
Namespaces are fundamental to computing systems. Each namespace maps the names that clients use to retrieve resources to the actual resources themselves. However, the indirection that namespaces provide introduces avenues of attack through the name resolution process. Adversaries can trick programs into accessing unintended resources by changing the binding between names and resources and by using names whose target resources are ambiguous. In this paper, we explore whether a unified system approach may be found to prevent many name resolution attacks. For this, we examine attacks on various namespaces and use these to derive invariants to defend against these attacks. Four prior techniques are identified that enforce aspects of name resolution, so we explore how these techniques address the proposed invariants. We find that each of these techniques are incomplete in themselves, but a combination could provide effective enforcement of the invariants. We implement a prototype system that can implement these techniques for the Linux file system namespace, and show that invariant rules specific to each, individual program system call can be enforced with a small overhead (less than 3%), indicating that fine-grained name resolution enforcement may be practical.
Keywords :
Linux; file organisation; Linux file system namespace; name resolution process; resource retrieval; Androids; Context; Linux; Permission; Process control; Servers;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Network Defense (EC2ND), 2011 Seventh European Conference on
Conference_Location :
Gothenburg
Print_ISBN :
978-1-4673-2116-7
Type :
conf
DOI :
10.1109/EC2ND.2011.17
Filename :
6377755
Link To Document :
بازگشت