HODOR: Reducing Attack Surface on Node.js via System Call Limitation

  Рет қаралды 651

Black Hat

Black Hat

Күн бұрын

....To address the above challenges, we will present HODOR, a lightweight system call level protection mechanism designed for Node.js applications. HODOR begins with cross-language and combined static-dynamic call graph analysis for both Node.js applications and the Node.js framework. This step involves proposing optimizations to enhance state-of-the-art call graph building methods, static-dynamic call graph analysis, and consideration of built-in methods for JavaScript code, along with partial context-sensitive mechanisms for C/C++ code. HODOR then generates system call whitelists tailored to different types of threads within the Node.js framework. Finally, HODOR implements lightweight system call restrictions based on the Seccomp mechanism, specifically applied to various threads of Node.js at carefully chosen moments...
By: Wang Gao , Dawu Gu , Xingwei Lin , Wenya Wang , Jingyi Wang
Full Abstract and Presentation Materials:
www.blackhat.c...

Пікірлер
Google’s Quantum Chip: Did We Just Tap Into Parallel Universes?
9:34
99.9% IMPOSSIBLE
00:24
STORROR
Рет қаралды 31 МЛН
So Cute 🥰 who is better?
00:15
dednahype
Рет қаралды 19 МЛН
Cheerleader Transformation That Left Everyone Speechless! #shorts
00:27
Fabiosa Best Lifehacks
Рет қаралды 16 МЛН
Privacy Detective: Sniffing Out Your Data Leaks for Android
30:04
How to Incorporate wolfSSH in Your Yocto Builds
26:00
Black Hat USA 2024 Highlights
2:26
Black Hat
Рет қаралды 2 М.
Practical LLM Security: Takeaways From a Year in the Trenches
37:01
Keynote - Securing Our Cyberspace Together
1:02:26
Black Hat
Рет қаралды 2,1 М.
99.9% IMPOSSIBLE
00:24
STORROR
Рет қаралды 31 МЛН