ACHyb: a hybrid analysis approach to detect kernel access control vulnerabilities
Abstract
Access control is essential for the Operating System (OS) security. Incorrect implementation of access control can introduce new attack surfaces to the OS, known as Kernel Access Control Vulnerabilities (KACVs). To understand KACVs, we conduct our study on the root causes and the security impacts of KACVs. Regarding the complexity of the recognized root causes, we particularly focus on two kinds of KACVs, namely KACV-M (due to missing permission checks) and KACV-I (due to misusing permission checks). We find that over 60% of these KACVs are of critical, high or medium security severity, resulting in a variety of security threats including bypass security checking, privileged escalation, etc. However, existing approaches can only detect KACV-M. The state-of-the-art KACV-M detector called PeX is a static analysis tool, which still suffers from extremely high false-positive rates.
BibTeX
@inproceedings{Hu-al:FSE21,
author = {Yang Hu and
Wenxi Wang and
Casen Hunger and
Riley Wood and
Sarfraz Khurshid and
Mohit Tiwari},
title = {{ACHyb:} a hybrid analysis approach to detect kernel access control vulnerabilities},
booktitle = {{ESEC/SIGSOFT} {FSE}},
pages = {316--327},
publisher = {{ACM}},
year = {2021},
}