Automatic source code decomposition for privilege separation

Markus Trapp, Michael Rossberg, Guenter Schaefer · 2016

Privilege separation has been proposed to reduce exploitation capabilities attackers may gain after successfully infiltrating a process, e.g. a network daemon. In this article we present a highly automated approach for decomposition of existing source code in order to realize such a privilege separation for existing monolithic software. For this, we describe an approach to analyze the source code, generating necessary inter-process communication (IPC), global variable handling and a dynamic memory monitoring. To show practical suitability, the approach is evaluated by being applied to two open source network daemons.

Read the paper · More papers on PaperTik