An analysis on the impact and detection of kernel stack infoleaks

dc.contributor.affiliationDepartamento de Informática de Sistemas y Computadores
dc.contributor.affiliationInstituto Universitario de Automática e Informática Industrial
dc.contributor.affiliationEscuela Técnica Superior de Ingeniería Informática
dc.contributor.authorPeiró Frasquet, Salvadores_ES
dc.contributor.authorMuñoz Alcobendas, Manueles_ES
dc.contributor.authorCrespo, Alfons
dc.contributor.funderEuropean Commission
dc.contributor.funderMinisterio de Ciencia e Innovación
dc.contributor.funderMinisterio de Economía y Competitividad
dc.date.accessioned2017-06-29T12:35:54Z
dc.date.available2017-06-29T12:35:54Z
dc.date.issued2016
dc.descriptionThis is a pre-copyedited, author-produced PDF of an article accepted for publication in Logic Journal of the IGPL following peer review. The version of record An analysis on the impact and detection of kernel stack infoleaks. Logic Journal of the IGPL, 24(6), 899-915. is available online at: https://academic.oup.com/jigpal/issue/24/6.es_ES
dc.description.abstract[EN] The Linux kernel has become a fundamental component of mainstream computing solutions, now being used in a wide range of applications ranging from consumer electronics to cloud and server solutions. Being expected to continue its growth, especially in the mission-critical workloads. Parallel to the Linux adoption has increased its misuse by attackers and malicious users. This has increased attention paid to kernel security through the deployment of kernel protection mechanisms. Kernel-based attacks require reliability, where kernel attack reliability is achieved through the information gathering stage, where the attacker is able to gather enough information about the target to succeed. The taxonomy of kernel vulnerabilities includes information leaks (CWE-200), that are a class of vulnerabilities that permit access to the kernel memory layout and contents. Information leaks can improve the attack reliability enabling the attacker to read sensitive kernel data to bypass kernel based protections. In this work, we aim at the analysis and detection of stack-based information leaks to harden the security of the kernel. First, we analyse the problem of kernel infoleaks in Section 3, next, we examine the impact of infoleaks attacks on the security of the kernel in Section 4. Then, we present a technique for detecting kernel based infoleaks through static analysis Section 5. Next, we evaluate our technique by applying it to the Linux kernel in Section 6. Finally, we discuss the applications and limitations of our work (Section 6.3) and finally we draw our concluding remarks.en_EN
dc.description.accrualMethodSes_ES
dc.description.bibliographicCitationPeiró Frasquet, S.; Muñoz Alcobendas, M.; Crespo Lorente, A. (2016). An analysis on the impact and detection of kernel stack infoleaks. Logic Journal of the IGPL. 24(6):899-915. https://doi.org/10.1093/jigpal/jzw049es_ES
dc.description.issue6es_ES
dc.description.sponsorshipThe author wants to thank all the people that contributed to make this work possible. This work has been partially supported by the Spanish Government Research Office under grant TIN2014-56158-C4-1-P, TIN2014-56158-C4-4-P and EU Project DREAMS FP7-ICT- 610640.en_EN
dc.description.upvformatpfin915es_ES
dc.description.upvformatpinicio899es_ES
dc.description.volume24es_ES
dc.identifier.doi10.1093/jigpal/jzw049
dc.identifier.issn1367-0751
dc.identifier.urihttps://riunet.upv.es/handle/10251/84113
dc.languageIngléses_ES
dc.publisherOxford University Press (OUP)es_ES
dc.relation.ispartofLogic Journal of the IGPLes_ES
dc.relation.projectIDinfo:eu-repo/grantAgreement/EC/FP7/610640/EU/Distributed REal-Time Architecture for Mixed Criticality Systems/es_ES
dc.relation.projectIDinfo:eu-repo/grantAgreement/MINECO//TIN2014-56158-C4-1-P/ES/SISTEMAS CIBER-FISICOS DE CRITICIDAD MIXTA SOBRE PLATAFORMAS MULTINUCLEO/es_ES
dc.relation.projectIDinfo:eu-repo/grantAgreement/MINECO//TIN2014-56158-C4-4-P/ES/CODISEÑO DE SISTEMAS DE CONTROL CON CRITICIDAD MIXTA BASADO EN MISIONES/
dc.relation.publisherversionhttp://dx.doi.org/10.1093/jigpal/jzw049es_ES
dc.relation.senia336744es_ES
dc.rightsReserva de todos los derechoses_ES
dc.rights.accessRightsAbiertoes_ES
dc.subjectConfidentialityes_ES
dc.subjectInformation securityes_ES
dc.subjectInformation disclosure (Infoleak)es_ES
dc.subjectkerneles_ES
dc.subjectOperating systemes_ES
dc.titleAn analysis on the impact and detection of kernel stack infoleakses_ES
dc.typeArtículoes_ES
dc.type.versioninfo:eu-repo/semantics/publishedVersiones_ES
dspace.entity.typePublication
person.identifier3009
person.identifier.orcid0000-0002-6606-7406
relation.isAuthorOfPublication0df0e67b-2788-404c-8d57-8ccc0e3d61fd
relation.isAuthorOfPublication.latestForDiscovery0df0e67b-2788-404c-8d57-8ccc0e3d61fd
relation.isOrgUnitOfPublicationd1ff3d29-c17c-4a84-bfc3-4f72ea62b663
relation.isOrgUnitOfPublication4da5e82d-4dc1-4f6f-b1c3-f30b0be2adce
relation.isOrgUnitOfPublicationd307086e-520c-4cdc-8116-d7178d71bfdc
relation.isOrgUnitOfPublication.latestForDiscoveryd1ff3d29-c17c-4a84-bfc3-4f72ea62b663
upv.uuidb36b2122-60f7-41f8-9f59-c7c105320161es_ES

Archivos

Bloque original

Mostrando 1 - 1 de 1
Cargando...
Miniatura
Nombre:
ileak-analysis.pdf
Tamaño:
614.87 KB
Formato:
Adobe Portable Document Format
Descripción:
Versión del Autor.