- Home
- Search Results
- Page 1 of 1
Search for: All records
-
Total Resources3
- Resource Type
-
0003000000000000
- More
- Availability
-
30
- Author / Contributor
- Filter by Author / Creator
-
-
Atayde, Lucas (3)
-
Palmer, Imani (3)
-
Roessler, Nick (3)
-
Bates, Adam (2)
-
Dautenhahn, Nathan (2)
-
McKee, Derrick (2)
-
Pandey, Jai (2)
-
Payer, Mathias (2)
-
Chien, Yi (1)
-
DeHon, Andre (1)
-
DeHon, André (1)
-
Gray, Lily (1)
-
Kemerlis, Vasileios P (1)
-
Kemerlis, Vasileios P. (1)
-
Smith, Jonathan M (1)
-
Smith, Jonathan M. (1)
-
Yang, Peiru (1)
-
#Tyler Phillips, Kenneth E. (0)
-
#Willis, Ciara (0)
-
& Abreu-Ramos, E. D. (0)
-
- Filter by Editor
-
-
null (2)
-
& Spizer, S. M. (0)
-
& . Spizer, S. (0)
-
& Ahn, J. (0)
-
& Bateiha, S. (0)
-
& Bosch, N. (0)
-
& Brennan K. (0)
-
& Brennan, K. (0)
-
& Chen, B. (0)
-
& Chen, Bodong (0)
-
& Drown, S. (0)
-
& Ferretti, F. (0)
-
& Higgins, A. (0)
-
& J. Peters (0)
-
& Kali, Y. (0)
-
& Ruiz-Arias, P.M. (0)
-
& S. Spitzer (0)
-
& Sahin. I. (0)
-
& Spitzer, S. (0)
-
& Spitzer, S.M. (0)
-
-
Have feedback or suggestions for a way to improve these results?
!
Note: When clicking on a Digital Object Identifier (DOI) number, you will be taken to an external site maintained by the publisher.
Some full text articles may not yet be available without a charge during the embargo (administrative interval).
What is a DOI Number?
Some links on this page may take you to non-federal websites. Their policies may differ from this site.
-
μSCOPE: A Methodology for Analyzing Least-Privilege Compartmentalization in Large Software ArtifactsRoessler, Nick; Atayde, Lucas; Palmer, Imani; McKee, Derrick; Pandey, Jai; Kemerlis, Vasileios P; Payer, Mathias; Bates, Adam; DeHon, André; Smith, Jonathan M (, The 24th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2021))null (Ed.)
-
μSCOPE: A Methodology for Analyzing Least-Privilege Compartmentalization in Large Software ArtifactsRoessler, Nick; Atayde, Lucas; Palmer, Imani; McKee, Derrick; Pandey, Jai; Kemerlis, Vasileios P.; Payer, Mathias; Bates, Adam; Smith, Jonathan M.; DeHon, Andre; et al (, 24th International Symposium on Research in Attacks, Intrusions and Defenses)By prioritizing simplicity and portability, least-privilege engineering has been an afterthought in OS design, resulting in monolithic kernels where any exploit leads to total compromise. μSCOPE (“microscope”) addresses this problem by automatically identifying opportunities for least-privilege separation. μSCOPE replaces expert-driven, semi-automated analysis with a general methodology for exploring a continuum of security vs. performance design points by adopting a quantitative and systematic approach to privilege analysis. We apply the μSCOPE methodology to the Linux kernel by (1) instrumenting the entire kernel to gain comprehensive, fine-grained memory access and call activity; (2) mapping these accesses to semantic information; and (3) conducting separability analysis on the kernel using both quantitative privilege and overhead metrics. We discover opportunities for orders of magnitude privilege reduction while predicting relatively low overheads—at 15% mediation overhead, overprivilege in Linux can be reduced up to 99.8%—suggesting fine-grained privilege separation is feasible and laying the groundwork for accelerating real privilege separation.more » « less
An official website of the United States government

Full Text Available