Attackers as Instructors: Using Container Isolation to Reduce Risk and Understand Vulnerabilities


연구 분야: Strategies



학회: International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment


초록

To achieve economies of scale, popular Internet destinations concurrently serve hundreds or thousands of users on shared physical infrastructure. This resource sharing enables attacks that misuse permissions and affect other users. Our work uses containerization to create “single-use servers” which are dynamically instantiated and tailored for each user’s permissions. This isolates users and eliminates attacker persistence. Further, it simplifies analysis, allowing the fusion of logs to help defenders localize vulnerabilities associated with security incidents. We thus mitigate attacks and convert them into debugging traces to aid remediation. We evaluate the approach using three systems, including the popular WordPress content management system. It eliminates attacker persistence, propagation, and permission misuse. It has low CPU and latency costs and requires linear memory consumption, which we reduce with a customized page merging technique.


Author Profile
Yunsen Lei

Worcester Polytechnic Institute Worcester MA USA

Morocco
Author Profile
Julian P. Lanson

Worcester Polytechnic Institute Worcester MA USA

Morocco
Author Profile
Craig A. Shue

Worcester Polytechnic Institute Worcester MA USA

Morocco

📄 논문 정보

발행 연도 2023년
인용수 0
출판 국가 Morocco, United States
사이트 Springer
좋아요 수 0

연관 논문 목록 (142건)