Sciweavers

NDSS
2005
IEEE

A Black-Box Tracing Technique to Identify Causes of Least-Privilege Incompatibilities

13 years 10 months ago
A Black-Box Tracing Technique to Identify Causes of Least-Privilege Incompatibilities
Most Windows users run all the time with Admin privileges. This significantly increases the vulnerability of Windows systems because the compromise of any user-level application becomes a system compromise. To address this problem, we present a novel tracing technique to identify the causes of least-privilege incompatibilities (i.e., application dependencies on Admin privileges). Our evaluation on a number of real-world applications shows that our tracing technique significantly helps developers fix leastprivilege incompatibilities, and can also help system administrators mitigate the impact of least-privilege incompatibilities through local system policy changes.
Shuo Chen, John Dunagan, Chad Verbowski, Yi-Min Wa
Added 25 Jun 2010
Updated 25 Jun 2010
Type Conference
Year 2005
Where NDSS
Authors Shuo Chen, John Dunagan, Chad Verbowski, Yi-Min Wang
Comments (0)