trustBT Ensuring a Secure Execution Environment in User Space Using the fastBT Framework
Antonio Barresi · 2009
In the days of zero-day exploits and automated exploitation of software vulnerabilities the need for proactive protection mechanisms against unknown vulnerabilities increases. Dynamic binary translation is a promising technology for many application areas and can also be used for implementing a secure execution environment to secure software execution during runtime. This thesis focuses on exploring conceptionally how dynamic binary translation can be used in the area of software security. To proof the concepts trustBT was developed as an extension to secuBT both based on the fastBT dynamic binary translation framework. trustBT mainly adds a policy-based system call sandbox which allows to easily restrict programs on a system call level. The policy-based approach allows to express strict limitations in a flexible way. trustBT allows to execute untrusted binaries or to restrict the damage potential of malicious code executed in the context of a trusted binary. The additional overhead introduced by the system call verification is low. Additional protection mechanisms implemented by secuBT help protecting a program against exploitation of unknown vulnerabilities. All the protection mechanisms are deployed without kernel modifications or recompilation of the program.