Countdown: mitigation of software exploitation using usage count-based system call filterCountdown: 사용 횟수 기반 시스템 호출 필터를 통한 소프트웨어 익스플로잇 방어

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 270
  • Download : 0
DC FieldValueLanguage
dc.contributor.advisorKang, Brent Byunghoon-
dc.contributor.advisor강병훈-
dc.contributor.authorLim, Chang-il-
dc.date.accessioned2022-04-27T19:32:22Z-
dc.date.available2022-04-27T19:32:22Z-
dc.date.issued2021-
dc.identifier.urihttp://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=963567&flag=dissertationen_US
dc.identifier.urihttp://hdl.handle.net/10203/296188-
dc.description학위논문(석사) - 한국과학기술원 : 정보보호대학원, 2021.8,[iv, 23 p. :]-
dc.description.abstractSystem calls have always been abused for many software exploitations. Although modern operating systems have mechanisms to filter the unnecessary system calls, their approach supports only policies of allowing or rejecting, requires manual configuration, and often fails to depend against sophisticated exploits that utilize only permitted system calls. This research suggests a more fine-granular methodology to restrict critical but rarely utilized system calls based on the number of usages. The filtering rules for system calls are generated by dynamically profiling the target applications and are enforced during runtime. The prototype of this research analyzed real-world applications to determine usage limits for each system call. The results show that it can reduce attack surfaces without harming the programs' functionalities, incurring similar performance overhead as a basic filtering mechanism Linux provides. Since the usage limits are automatically found for each system call, it can be practically applied without manual inspection of software source code.-
dc.languageeng-
dc.publisher한국과학기술원-
dc.subjectsystem call filter▼asoftware exploit mitigation▼aprinciple of least privilege▼asandbox▼asystem security-
dc.subject시스템 호출 필터▼a소프트웨어 익스플로잇 방어▼a최소 권한의 원칙▼a샌드박스▼a시스템 보안-
dc.titleCountdown: mitigation of software exploitation using usage count-based system call filter-
dc.title.alternativeCountdown: 사용 횟수 기반 시스템 호출 필터를 통한 소프트웨어 익스플로잇 방어-
dc.typeThesis(Master)-
dc.identifier.CNRN325007-
dc.description.department한국과학기술원 :정보보호대학원,-
dc.contributor.alternativeauthor임창일-
Appears in Collection
IS-Theses_Master(석사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0