摘要
在分析了权限提升攻击一般步骤的基础上,针对其会在系统中留下的攻击痕击,提出了一种新的审计机制,即在每次通过调用系统函数execve执行新的应用程序时,跟踪进程的realuserID、effectiveID以及savedsetuser-ID值的变化,从而可以准确地检测出各种针对特权程序的权限提升攻击。
Providing a new aduiting mechanism for detecting authority promoting attack, based on modifing Linux kernel, adds aduiting mechanism in system call-execve. Through monitor the changes of process's real user ID, effective ID and save set-user-ID, it can exactly and effectively detect the authority promoting attacks.
出处
《科学技术与工程》
2006年第7期880-881,889,共3页
Science Technology and Engineering