HODOR: Reducing Attack Surface on Node.js via System Call Limitation

  Рет қаралды 528

Black Hat

Black Hat

2 ай бұрын

....To address the above challenges, we will present HODOR, a lightweight system call level protection mechanism designed for Node.js applications. HODOR begins with cross-language and combined static-dynamic call graph analysis for both Node.js applications and the Node.js framework. This step involves proposing optimizations to enhance state-of-the-art call graph building methods, static-dynamic call graph analysis, and consideration of built-in methods for JavaScript code, along with partial context-sensitive mechanisms for C/C++ code. HODOR then generates system call whitelists tailored to different types of threads within the Node.js framework. Finally, HODOR implements lightweight system call restrictions based on the Seccomp mechanism, specifically applied to various threads of Node.js at carefully chosen moments...
By: Wang Gao , Dawu Gu , Xingwei Lin , Wenya Wang , Jingyi Wang
Full Abstract and Presentation Materials:
www.blackhat.com/eu-23/briefi...

Пікірлер
New Techniques for Split-Second DNS Rebinding
31:20
Black Hat
Рет қаралды 1,3 М.
Кәріс өшін алды...| Synyptas 3 | 10 серия
24:51
MOM TURNED THE NOODLES PINK😱
00:31
JULI_PROETO
Рет қаралды 18 МЛН
Artificial Intelligence: The new attack surface
9:27
IBM Technology
Рет қаралды 27 М.
What is the "best way" to develop software applications?
18:37
Web Dev Cody
Рет қаралды 256 М.
Deep Learning Bootcamp: Kaiming He
1:15:46
MIT Schwarzman College of Computing
Рет қаралды 49 М.
How I’d learn ML in 2024 (if I could start over)
7:05
Boris Meinardus
Рет қаралды 878 М.
My 2 Year Journey of Learning C, in 9 minutes
8:42
VoxelRifts
Рет қаралды 542 М.