Skip to main navigation Skip to search Skip to main content

Tracer: Enforcing Mandatory Access Control in commodity OS with the support of light-weight intrusion detection and tracing

  • Renmin University of China
  • Stony Brook University
  • Industrial Technology Research Institute of Taiwan

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

5 Scopus citations

Abstract

Enforcing a practical Mandatory Access Control (MAC) in a commercial operating system to tackle malware problem is a grand challenge but also a promising approach. The firmest barriers to apply MAC to defeat malware programs are the incompatible and unusable problems in existing MAC systems. To address these issues, we start our work by analyzing the technical details of 2,600 malware samples one by one and performing experiments over two types of MAC enforced operating systems. Based on the preliminary studies, we design a novel MAC model incorporating intrusion detection and tracing in a commercial operating system, named Tracer, in order to disable malware on hosts while offering good compatibility to existing software and good usability to common users who are not system experts. The model conceptually consists of three actions: detecting, tracing and restricting suspected intruders. One novelty is that it leverages light-weight intrusion detection and tracing techniques to automate security label configuration that is widely acknowledged as a tough issue when applying a MAC system in practice. The other is that, rather than restricting information flow as a traditional MAC does, it traces intruders and restricts only their critical malware behaviors, where intruders represent processes and executables that are potential agents of a remote attacker. Our prototyping and experiments on Windows show that Tracer can effectively defeat all malware samples tested via blocking malware behaviors while not causing a significant compatibility problem.

Original languageEnglish
Title of host publicationProceedings of the 6th International Symposium on Information, Computer and Communications Security, ASIACCS 2011
PublisherAssociation for Computing Machinery
Pages135-144
Number of pages10
ISBN (Print)9781450305648
DOIs
StatePublished - 2011
Event6th International Symposium on Information, Computer and Communications Security, ASIACCS 2011 - Hong Kong, China
Duration: Mar 22 2011Mar 24 2011

Publication series

NameProceedings of the 6th International Symposium on Information, Computer and Communications Security, ASIACCS 2011

Conference

Conference6th International Symposium on Information, Computer and Communications Security, ASIACCS 2011
Country/TerritoryChina
CityHong Kong
Period03/22/1103/24/11

Keywords

  • Access control
  • Compatibility
  • Intrusion detection
  • Malware
  • Operating system
  • Usability

Fingerprint

Dive into the research topics of 'Tracer: Enforcing Mandatory Access Control in commodity OS with the support of light-weight intrusion detection and tracing'. Together they form a unique fingerprint.

Cite this