DC Field | Value | Language |
---|---|---|
dc.contributor.advisor | Kang, Brent Byunghoon | - |
dc.contributor.advisor | 강병훈 | - |
dc.contributor.author | Lim, Chang-il | - |
dc.date.accessioned | 2022-04-27T19:32:22Z | - |
dc.date.available | 2022-04-27T19:32:22Z | - |
dc.date.issued | 2021 | - |
dc.identifier.uri | http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=963567&flag=dissertation | en_US |
dc.identifier.uri | http://hdl.handle.net/10203/296188 | - |
dc.description | 학위논문(석사) - 한국과학기술원 : 정보보호대학원, 2021.8,[iv, 23 p. :] | - |
dc.description.abstract | System calls have always been abused for many software exploitations. Although modern operating systems have mechanisms to filter the unnecessary system calls, their approach supports only policies of allowing or rejecting, requires manual configuration, and often fails to depend against sophisticated exploits that utilize only permitted system calls. This research suggests a more fine-granular methodology to restrict critical but rarely utilized system calls based on the number of usages. The filtering rules for system calls are generated by dynamically profiling the target applications and are enforced during runtime. The prototype of this research analyzed real-world applications to determine usage limits for each system call. The results show that it can reduce attack surfaces without harming the programs' functionalities, incurring similar performance overhead as a basic filtering mechanism Linux provides. Since the usage limits are automatically found for each system call, it can be practically applied without manual inspection of software source code. | - |
dc.language | eng | - |
dc.publisher | 한국과학기술원 | - |
dc.subject | system call filter▼asoftware exploit mitigation▼aprinciple of least privilege▼asandbox▼asystem security | - |
dc.subject | 시스템 호출 필터▼a소프트웨어 익스플로잇 방어▼a최소 권한의 원칙▼a샌드박스▼a시스템 보안 | - |
dc.title | Countdown: mitigation of software exploitation using usage count-based system call filter | - |
dc.title.alternative | Countdown: 사용 횟수 기반 시스템 호출 필터를 통한 소프트웨어 익스플로잇 방어 | - |
dc.type | Thesis(Master) | - |
dc.identifier.CNRN | 325007 | - |
dc.description.department | 한국과학기술원 :정보보호대학원, | - |
dc.contributor.alternativeauthor | 임창일 | - |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.