The Experts below are selected from a list of 108 Experts worldwide ranked by ideXlab platform
Masaki Hashimoto - One of the best experts on this subject based on the ideXlab platform.
-
Additional kernel observer: Privilege Escalation Attack prevention mechanism focusing on system call Privilege changes
International Journal of Information Security, 2020Co-Authors: Toshihiro Yamauchi, Ryota Yoshitani, Yohei Akao, Yuichi Nakamura, Masaki HashimotoAbstract:CyberAttacks, especially Attacks that exploit operating system vulnerabilities, have been increasing in recent years. In particular, if administrator Privileges are acquired by an Attacker through a Privilege Escalation Attack, the Attacker can operate the entire system and cause serious damage. In this paper, we propose an additional kernel observer (AKO) that prevents Privilege Escalation Attacks that exploit operating system vulnerabilities. We focus on the fact that a process Privilege can be changed only by specific system calls. AKO monitors Privilege information changes during system call processing. If AKO detects a Privilege change after system call processing, whereby the invoked system call does not originally change the process Privilege, AKO regards the change as a Privilege Escalation Attack and applies countermeasures against it. AKO can therefore prevent Privilege Escalation Attacks. Introducing the proposed method in advance can prevent this type of Attack by changing any process Privilege that was not originally changed in a system call, regardless of the vulnerability type. In this paper, we describe the design and implementation of AKO for Linux x86 64-bit. Moreover, we show that AKO can be expanded to prevent the falsification of various data in the kernel space. Then, we present an expansion example that prevents the invalidation of Security-Enhanced Linux. Finally, our evaluation results show that AKO is effective against Privilege Escalation Attacks, while maintaining low overhead.
-
Additional Kernel Observer to Prevent Privilege Escalation Attacks by Focusing on System Call Privilege Changes
2018 IEEE Conference on Dependable and Secure Computing (DSC), 2018Co-Authors: Toshihiro Yamauchi, Ryota Yoshitani, Yohei Akao, Yuichi Nakamura, Masaki HashimotoAbstract:In recent years, there has been an increase in Attacks that exploit operating system vulnerabilities. In particular, if an administrator's Privilege is acquired by an Attacker through a Privilege Escalation Attack, the Attacker can operate the entire system and the system can suffer serious damage. In this paper, an additional kernel observer (AKO) method is proposed. It prevents Privilege Escalation Attacks that exploit operating system vulnerabilities. We focus on the fact that a process Privilege can be changed only by specific system calls. AKO monitors Privilege information changes during system call processing. If AKO detects a Privilege change after system call processing, whereby the invoked system call does not originally change the process Privilege, AKO regards the change as a Privilege Escalation Attack and applies countermeasures against it. In this paper, we describe the design and implementation of AKO for Linux x86, 64 bit. Moreover, AKO can be expanded to prevent the falsification of various data in the kernel space. We present an expansion example that prevents the invalidation of Security-Enhanced Linux. Evaluation results show that AKO is effective against Privilege Escalation Attacks, while maintaining low overhead.
Toshihiro Yamauchi - One of the best experts on this subject based on the ideXlab platform.
-
Additional kernel observer: Privilege Escalation Attack prevention mechanism focusing on system call Privilege changes
International Journal of Information Security, 2020Co-Authors: Toshihiro Yamauchi, Ryota Yoshitani, Yohei Akao, Yuichi Nakamura, Masaki HashimotoAbstract:CyberAttacks, especially Attacks that exploit operating system vulnerabilities, have been increasing in recent years. In particular, if administrator Privileges are acquired by an Attacker through a Privilege Escalation Attack, the Attacker can operate the entire system and cause serious damage. In this paper, we propose an additional kernel observer (AKO) that prevents Privilege Escalation Attacks that exploit operating system vulnerabilities. We focus on the fact that a process Privilege can be changed only by specific system calls. AKO monitors Privilege information changes during system call processing. If AKO detects a Privilege change after system call processing, whereby the invoked system call does not originally change the process Privilege, AKO regards the change as a Privilege Escalation Attack and applies countermeasures against it. AKO can therefore prevent Privilege Escalation Attacks. Introducing the proposed method in advance can prevent this type of Attack by changing any process Privilege that was not originally changed in a system call, regardless of the vulnerability type. In this paper, we describe the design and implementation of AKO for Linux x86 64-bit. Moreover, we show that AKO can be expanded to prevent the falsification of various data in the kernel space. Then, we present an expansion example that prevents the invalidation of Security-Enhanced Linux. Finally, our evaluation results show that AKO is effective against Privilege Escalation Attacks, while maintaining low overhead.
-
Additional Kernel Observer to Prevent Privilege Escalation Attacks by Focusing on System Call Privilege Changes
2018 IEEE Conference on Dependable and Secure Computing (DSC), 2018Co-Authors: Toshihiro Yamauchi, Ryota Yoshitani, Yohei Akao, Yuichi Nakamura, Masaki HashimotoAbstract:In recent years, there has been an increase in Attacks that exploit operating system vulnerabilities. In particular, if an administrator's Privilege is acquired by an Attacker through a Privilege Escalation Attack, the Attacker can operate the entire system and the system can suffer serious damage. In this paper, an additional kernel observer (AKO) method is proposed. It prevents Privilege Escalation Attacks that exploit operating system vulnerabilities. We focus on the fact that a process Privilege can be changed only by specific system calls. AKO monitors Privilege information changes during system call processing. If AKO detects a Privilege change after system call processing, whereby the invoked system call does not originally change the process Privilege, AKO regards the change as a Privilege Escalation Attack and applies countermeasures against it. In this paper, we describe the design and implementation of AKO for Linux x86, 64 bit. Moreover, AKO can be expanded to prevent the falsification of various data in the kernel space. We present an expansion example that prevents the invalidation of Security-Enhanced Linux. Evaluation results show that AKO is effective against Privilege Escalation Attacks, while maintaining low overhead.
Ryota Yoshitani - One of the best experts on this subject based on the ideXlab platform.
-
Additional kernel observer: Privilege Escalation Attack prevention mechanism focusing on system call Privilege changes
International Journal of Information Security, 2020Co-Authors: Toshihiro Yamauchi, Ryota Yoshitani, Yohei Akao, Yuichi Nakamura, Masaki HashimotoAbstract:CyberAttacks, especially Attacks that exploit operating system vulnerabilities, have been increasing in recent years. In particular, if administrator Privileges are acquired by an Attacker through a Privilege Escalation Attack, the Attacker can operate the entire system and cause serious damage. In this paper, we propose an additional kernel observer (AKO) that prevents Privilege Escalation Attacks that exploit operating system vulnerabilities. We focus on the fact that a process Privilege can be changed only by specific system calls. AKO monitors Privilege information changes during system call processing. If AKO detects a Privilege change after system call processing, whereby the invoked system call does not originally change the process Privilege, AKO regards the change as a Privilege Escalation Attack and applies countermeasures against it. AKO can therefore prevent Privilege Escalation Attacks. Introducing the proposed method in advance can prevent this type of Attack by changing any process Privilege that was not originally changed in a system call, regardless of the vulnerability type. In this paper, we describe the design and implementation of AKO for Linux x86 64-bit. Moreover, we show that AKO can be expanded to prevent the falsification of various data in the kernel space. Then, we present an expansion example that prevents the invalidation of Security-Enhanced Linux. Finally, our evaluation results show that AKO is effective against Privilege Escalation Attacks, while maintaining low overhead.
-
Additional Kernel Observer to Prevent Privilege Escalation Attacks by Focusing on System Call Privilege Changes
2018 IEEE Conference on Dependable and Secure Computing (DSC), 2018Co-Authors: Toshihiro Yamauchi, Ryota Yoshitani, Yohei Akao, Yuichi Nakamura, Masaki HashimotoAbstract:In recent years, there has been an increase in Attacks that exploit operating system vulnerabilities. In particular, if an administrator's Privilege is acquired by an Attacker through a Privilege Escalation Attack, the Attacker can operate the entire system and the system can suffer serious damage. In this paper, an additional kernel observer (AKO) method is proposed. It prevents Privilege Escalation Attacks that exploit operating system vulnerabilities. We focus on the fact that a process Privilege can be changed only by specific system calls. AKO monitors Privilege information changes during system call processing. If AKO detects a Privilege change after system call processing, whereby the invoked system call does not originally change the process Privilege, AKO regards the change as a Privilege Escalation Attack and applies countermeasures against it. In this paper, we describe the design and implementation of AKO for Linux x86, 64 bit. Moreover, AKO can be expanded to prevent the falsification of various data in the kernel space. We present an expansion example that prevents the invalidation of Security-Enhanced Linux. Evaluation results show that AKO is effective against Privilege Escalation Attacks, while maintaining low overhead.
Yohei Akao - One of the best experts on this subject based on the ideXlab platform.
-
Additional kernel observer: Privilege Escalation Attack prevention mechanism focusing on system call Privilege changes
International Journal of Information Security, 2020Co-Authors: Toshihiro Yamauchi, Ryota Yoshitani, Yohei Akao, Yuichi Nakamura, Masaki HashimotoAbstract:CyberAttacks, especially Attacks that exploit operating system vulnerabilities, have been increasing in recent years. In particular, if administrator Privileges are acquired by an Attacker through a Privilege Escalation Attack, the Attacker can operate the entire system and cause serious damage. In this paper, we propose an additional kernel observer (AKO) that prevents Privilege Escalation Attacks that exploit operating system vulnerabilities. We focus on the fact that a process Privilege can be changed only by specific system calls. AKO monitors Privilege information changes during system call processing. If AKO detects a Privilege change after system call processing, whereby the invoked system call does not originally change the process Privilege, AKO regards the change as a Privilege Escalation Attack and applies countermeasures against it. AKO can therefore prevent Privilege Escalation Attacks. Introducing the proposed method in advance can prevent this type of Attack by changing any process Privilege that was not originally changed in a system call, regardless of the vulnerability type. In this paper, we describe the design and implementation of AKO for Linux x86 64-bit. Moreover, we show that AKO can be expanded to prevent the falsification of various data in the kernel space. Then, we present an expansion example that prevents the invalidation of Security-Enhanced Linux. Finally, our evaluation results show that AKO is effective against Privilege Escalation Attacks, while maintaining low overhead.
-
Additional Kernel Observer to Prevent Privilege Escalation Attacks by Focusing on System Call Privilege Changes
2018 IEEE Conference on Dependable and Secure Computing (DSC), 2018Co-Authors: Toshihiro Yamauchi, Ryota Yoshitani, Yohei Akao, Yuichi Nakamura, Masaki HashimotoAbstract:In recent years, there has been an increase in Attacks that exploit operating system vulnerabilities. In particular, if an administrator's Privilege is acquired by an Attacker through a Privilege Escalation Attack, the Attacker can operate the entire system and the system can suffer serious damage. In this paper, an additional kernel observer (AKO) method is proposed. It prevents Privilege Escalation Attacks that exploit operating system vulnerabilities. We focus on the fact that a process Privilege can be changed only by specific system calls. AKO monitors Privilege information changes during system call processing. If AKO detects a Privilege change after system call processing, whereby the invoked system call does not originally change the process Privilege, AKO regards the change as a Privilege Escalation Attack and applies countermeasures against it. In this paper, we describe the design and implementation of AKO for Linux x86, 64 bit. Moreover, AKO can be expanded to prevent the falsification of various data in the kernel space. We present an expansion example that prevents the invalidation of Security-Enhanced Linux. Evaluation results show that AKO is effective against Privilege Escalation Attacks, while maintaining low overhead.
Yuichi Nakamura - One of the best experts on this subject based on the ideXlab platform.
-
Additional kernel observer: Privilege Escalation Attack prevention mechanism focusing on system call Privilege changes
International Journal of Information Security, 2020Co-Authors: Toshihiro Yamauchi, Ryota Yoshitani, Yohei Akao, Yuichi Nakamura, Masaki HashimotoAbstract:CyberAttacks, especially Attacks that exploit operating system vulnerabilities, have been increasing in recent years. In particular, if administrator Privileges are acquired by an Attacker through a Privilege Escalation Attack, the Attacker can operate the entire system and cause serious damage. In this paper, we propose an additional kernel observer (AKO) that prevents Privilege Escalation Attacks that exploit operating system vulnerabilities. We focus on the fact that a process Privilege can be changed only by specific system calls. AKO monitors Privilege information changes during system call processing. If AKO detects a Privilege change after system call processing, whereby the invoked system call does not originally change the process Privilege, AKO regards the change as a Privilege Escalation Attack and applies countermeasures against it. AKO can therefore prevent Privilege Escalation Attacks. Introducing the proposed method in advance can prevent this type of Attack by changing any process Privilege that was not originally changed in a system call, regardless of the vulnerability type. In this paper, we describe the design and implementation of AKO for Linux x86 64-bit. Moreover, we show that AKO can be expanded to prevent the falsification of various data in the kernel space. Then, we present an expansion example that prevents the invalidation of Security-Enhanced Linux. Finally, our evaluation results show that AKO is effective against Privilege Escalation Attacks, while maintaining low overhead.
-
Additional Kernel Observer to Prevent Privilege Escalation Attacks by Focusing on System Call Privilege Changes
2018 IEEE Conference on Dependable and Secure Computing (DSC), 2018Co-Authors: Toshihiro Yamauchi, Ryota Yoshitani, Yohei Akao, Yuichi Nakamura, Masaki HashimotoAbstract:In recent years, there has been an increase in Attacks that exploit operating system vulnerabilities. In particular, if an administrator's Privilege is acquired by an Attacker through a Privilege Escalation Attack, the Attacker can operate the entire system and the system can suffer serious damage. In this paper, an additional kernel observer (AKO) method is proposed. It prevents Privilege Escalation Attacks that exploit operating system vulnerabilities. We focus on the fact that a process Privilege can be changed only by specific system calls. AKO monitors Privilege information changes during system call processing. If AKO detects a Privilege change after system call processing, whereby the invoked system call does not originally change the process Privilege, AKO regards the change as a Privilege Escalation Attack and applies countermeasures against it. In this paper, we describe the design and implementation of AKO for Linux x86, 64 bit. Moreover, AKO can be expanded to prevent the falsification of various data in the kernel space. We present an expansion example that prevents the invalidation of Security-Enhanced Linux. Evaluation results show that AKO is effective against Privilege Escalation Attacks, while maintaining low overhead.