CASE: Minimizing Attack Surfaces Based on Context-Aware System Call Enforcement

Man-Ni Hsu, Tsung-Han Liu, Hsuan-Ying Lee, Chun‐Ying Huang · IEEE Transactions on Services Computing · 2025

Invoking system calls in exploit implementation is a typical approach to compromising a system. A key objective of these attacks is to manipulate program execution paths, with a specific focus on invoking targeted system calls. Our study introduces Context-Aware System Call Enforcement (CASE), a software-based approach meticulously crafted to shrink the attack surface associated with system call-based exploits. CASE achieves this by rigorously validating the context, mainly backward function call paths and runtime stack states, to ensure the legitimacy of system call invocations. Our strategy incorporates innovative elements, including anchored entry points, return address-based validation, and frame size checks. We formalize our approach by creating NP-hard challenges for potential attackers and complete with a proof-of-concept (PoC) implementation that shields against attacks. Our PoC implementation introduces minimal overhead, less than 2%, for context validation. Simultaneously, it adeptly identifies and halts attacks of varying complexities, ranging from simple examples to realworld servers.

Read the paper · More papers on PaperTik