HODOR: Reducing Attack Surface on Node.js via System Call Limitation

  Рет қаралды 611

Black Hat

Black Hat

6 ай бұрын

....To address the above challenges, we will present HODOR, a lightweight system call level protection mechanism designed for Node.js applications. HODOR begins with cross-language and combined static-dynamic call graph analysis for both Node.js applications and the Node.js framework. This step involves proposing optimizations to enhance state-of-the-art call graph building methods, static-dynamic call graph analysis, and consideration of built-in methods for JavaScript code, along with partial context-sensitive mechanisms for C/C++ code. HODOR then generates system call whitelists tailored to different types of threads within the Node.js framework. Finally, HODOR implements lightweight system call restrictions based on the Seccomp mechanism, specifically applied to various threads of Node.js at carefully chosen moments...
By: Wang Gao , Dawu Gu , Xingwei Lin , Wenya Wang , Jingyi Wang
Full Abstract and Presentation Materials:
www.blackhat.c...

Пікірлер
You Shall Not PASS - Analysing a NSO iOS Spyware Sample
40:22
Black Hat
Рет қаралды 3,1 М.
Cute
00:16
Oyuncak Avı
Рет қаралды 12 МЛН
Man Mocks Wife's Exercise Routine, Faces Embarrassment at Work #shorts
00:32
Fabiosa Best Lifehacks
Рет қаралды 4,4 МЛН
A Software Defined Radio (SDR) Approach to Radar
10:43
QIQ Systems
Рет қаралды 83 М.
Keynote - Securing Our Cyberspace Together
1:02:26
Black Hat
Рет қаралды 1 М.
Cute
00:16
Oyuncak Avı
Рет қаралды 12 МЛН