Loading…
Attending this event?
September 16-17, 2024 | Vienna, Austria
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Linux Security Summit Europe 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Central European Summer Time (UTC+2). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."
Tuesday September 17, 2024 14:00 - 14:30 CEST
Restricting system calls can significantly reduce the attack surface. However, solutions like seccomp can be bypassed(CVE-2009-0835, CVE-2019-2054, CVE-2023-2431, etc.). If unused syscalls can be eliminated at config level and compile time, the attack surface can be fundamentally controlled.
However, the widespread presence of .pushsection in kernel code prevents linker to perform code garbage collection. The associated KEEP() directive also causes ownership reversal issues, resulting in related sections that should be removed to remain, leaving more unused code for potential exploitation by hackers.
By systematically reworking the .pushsection directive, we propose dead syscalls elimination. After specifying the syscalls that need to be retained, it can remove other syscalls' code without affecting the normal operation of the kernel. Attackers cannot exploit something that does not exist. This not only reduces the kernel size and eliminates the overhead of seccomp but also completely eradicates the possibility of exploitation.
Besides, the approach of eliminating the KEEP() directive can be generalized, further reducing the kernel's dead code and decreasing the attack surface.
Speakers
avatar for Xiao Liu

Xiao Liu

research assistant, Yunnan University
A speaker from Yunnan University
avatar for Yuan Tan

Yuan Tan

Security Researcher, Lanzhou University
Student in Computer Science, specializing in security.
avatar for Siqi Fan

Siqi Fan

Lanzhou University
Tuesday September 17, 2024 14:00 - 14:30 CEST
Hall L3

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link