12th USENIX Security Symposium Abstract
Pp. 257-272 of the Proceedings
Improving Host Security with System Call Policies
Niels Provos, CITI, University of Michigan
Abstract
We introduce a system that eliminates the need to run programs in
privileged process contexts. Using our system, programs run
unprivileged but may execute certain operations with elevated
privileges as determined by a configurable policy eliminating the need
for suid or sgid binaries. We present the design and analysis of the
``Systrace'' facility which supports fine grained process confinement,
intrusion detection, auditing and privilege elevation. It also
facilitates the often difficult process of policy generation. With
Systrace, it is possible to generate policies automatically in a
training session or generate them interactively during program
execution. The policies describe the desired behavior of services or
user applications on a system call level and are enforced to prevent
operations that are not explicitly permitted. We show that Systrace
is efficient and does not impose significant performance penalties.
- View the full text of this paper in HTML and
PDF.
Until August 2004, you will need your USENIX membership identification in order to access the full papers. The Proceedings are published as a collective work, © 2003 by the USENIX Association. All Rights Reserved. Rights to individual papers remain with the author or the author's employer. Permission is granted for the noncommercial reproduction of the complete work for educational or research purposes. USENIX acknowledges all trademarks within this paper.
- If you need the latest Adobe Acrobat Reader, you can download it from Adobe's site.
|