1 of 37

Security

CS-446/646

C. Papachristos

Robotic Workers (RoboWork) Lab

University of Nevada, Reno

2 of 37

Mandatory Access Control

DAC vs MAC

Most people are familiar with Discretionary Access Control (DAC)

    • Unix Permission bits are an example
      • e.g. might set File private such that only Group friends can read it:
      • -rw-r––- 1 dm friends 1254 Feb 11 20:22 private
    • Anyone with access to information can further propagate that information at their discretion:
      • $ mail sigint@enemy.gov < private

Mandatory Access Control (MAC) can restrict Propagation

      • Note: MAC here not be confused with Message Authentication Codes or Medium Access Control
    • Security administrator may allow you to read but not disclose File

CS446/646 C. Papachristos

3 of 37

Mandatory Access Control

Mandatory Access Control Motivation

  • Prevent users from disclosing sensitive information (whether accidentally or maliciously)
    • e.g. Classified information requires such protection

  • Prevent Software from surreptitiously leaking data
    • Seemingly innocuous Software may steal secrets in the background
    • Such a program is known as a “Trojan Horse

  • Case study: Symantec AntiVirus 10
    • Contained a “Remote Exploit” (attacker could run arbitrary code)
    • Inherently required access to all of a user’s Files to scan them
    • Can an OS protect private (e.g. Classified) File contents under such circumstances?

CS446/646 C. Papachristos

4 of 37

Mandatory Access Control

Example: Anti-Virus (AV) Software

  • Scanner : Checks for Virus Signatures

  • Update Daemon : Downloads new Virus Signatures

  • How can OS enforce Security without blindly trusting AV Software?
    • Must not leak contents of your Files to Network
    • Must not tamper with contents of your Files

CS446/646 C. Papachristos

5 of 37

Mandatory Access Control

Example: Anti-Virus (AV) Software

  • Scanner can write your private data to Network

  • Prevent Scanner from invoking any System Call that might send a Network message?

CS446/646 C. Papachristos

6 of 37

Mandatory Access Control

Example: Anti-Virus (AV) Software

  • Scanner can send private data to Update Daemon

  • Update Daemon sends data over Network
    • Can cleverly disguise secrets in order/timing of update requests

  • Block Inter-Process Communication & Shared Memory–related System Calls in Scanner?

CS446/646 C. Papachristos

7 of 37

Mandatory Access Control

Example: Anti-Virus (AV) Software

  • Scanner can write data to world-readable File in /tmp

  • Update Daemon later reads and discloses File

  • Prevent Update Daemon from using /tmp?

CS446/646 C. Papachristos

8 of 37

Mandatory Access Control

Example: Anti-Virus (AV) Software

  • Scanner can acquire read Locks on Virus Signature Database
    • Encode private User data by Locking various ranges of File

  • Update Daemon decodes data by detecting Locks
    • Then disclose private User data over the Network

  • Have Trusted Software copy Virus DB for Scanner?

CS446/646 C. Papachristos

9 of 37

Mandatory Access Control

The list goes on…

  • Scanner can call setproctitle with User data
    • Update Daemon can then extract User data by running ps

  • Scanner can bind particular TCP or UDP Port numbers
    • Sends no Network traffic, but used Port numbers detectable by Update Daemon

  • Scanner can relay data through another Process
    • Call ptrace to take over Process, then write to Network
    • Use sendmail, httpd, or portmap to reveal data

  • Disclose data by modulating free Disk space

  • Can be certain we’ve covered all possible communication channels?
    • Not without a more systematic approach to the problem

C. Papachristos

10 of 37

Labels and Lattices

Secrecy / Confidentiality

  • Achieve Controlled Access to Classified information

Typical way to think of Security in this context:

  • A subject at a given Security Level should not be able to read information at higher Security levels, and
  • A subject at a given Security Level should not be able to write information (leak it) at lower Security levels

  • I.e. a User can create content only at or above their own Security Level (e.g. a Secret-level researcher can create Secret-level or Top-Secret-level Files but may not create Public-level Files). Conversely, a User can view content only at or below their own Security Level (e.g. a Secret-level researcher can view Public-level or Secret-level Files, but may not view Top-Secret-level Files).

  • Transfer of information from a high-Secrecy document to a lower-Secrecy�document may happen via Trusted subjects only

C. Papachristos

11 of 37

Labels and Lattices

 

C. Papachristos

12 of 37

Labels and Lattices

 

C. Papachristos

13 of 37

Labels and Lattices

 

C. Papachristos

14 of 37

Labels and Lattices

Labels form a Lattice [Denning]

CS446/646 C. Papachristos

15 of 37

Labels and Lattices

Labels form a Lattice [Denning]

CS446/646 C. Papachristos

16 of 37

Labels and Lattices

Labels form a Lattice [Denning]

CS446/646 C. Papachristos

17 of 37

Labels and Lattices

 

CS446/646 C. Papachristos

18 of 37

Labels and Lattices

 

CS446/646 C. Papachristos

19 of 37

Labels and Lattices

 

C. Papachristos

20 of 37

Labels and Lattices

 

CS446/646 C. Papachristos

21 of 37

Labels and Lattices

 

CS446/646 C. Papachristos

22 of 37

Labels and Lattices

 

CS446/646 C. Papachristos

23 of 37

Labels and Lattices

Still No: Timing Channels

  • Example: CPU Utilization
    • To send a 0 bit, use 100% of CPU in busy-loop
    • To send a 1 bit, sleep and relinquish CPU
    • Repeat to transfer more bits

  • Example: Resource Exhaustion
    • High Program allocates all Physical Memory if bit is 1
    • If Low Program slows down due to Paging, knows less Memory available

  • Other Examples:
    • Disk head position, Processor Cache/TLB pollution, …

CS446/646 C. Papachristos

24 of 37

Labels and Lattices

 

CS446/646 C. Papachristos

25 of 37

Labels and Lattices

Declassification

  • Sometimes need to prepare Unclassified report from Classified data

  • Declassification happens outside of traditional Access Control Model
    • Present File to security officer for downgrade

  • Job of Declassification often not trivial
    • e.g., Microsoft Word saves a lot of Undo information
      • This might be all the secret stuff you cut from document
    • Another bad mistake:
      • Redact PDF using black censor bars over or under text, leaving text selectable
        • e.g. [Cluley]

CS446/646 C. Papachristos

26 of 37

Labels and Lattices

Integrity

  • Achieve Controlled Access to Classified information

Typical way to think of Security in this context:

  • A Subject should not be able to corrupt Data in an Integrity Level ranked higher than themself
  • A Subject should not be able to become corrupted by Data from a lower Integrity Level

Preservation of data Integrity – Goals:

  • Prevent Data modification by unauthorized parties
  • Prevent unauthorized Data modification by authorized parties
  • Maintain Internal and External Consistency (i.e. Data reflects the real world)

C. Papachristos

27 of 37

Labels and Lattices

 

C. Papachristos

28 of 37

LOMAC

LOMAC [Fraser]

  • MAC not widely accepted outside military

Low water-Mark Access Control (LOMAC)’s goal:

    • Make MAC more palatable

  • Concentrates on Integrity
    • More important goal for many settings
      • e.g. don’t want Viruses tampering with all your Files
    • Also don’t have to worry as much about Covert Channels

  • Provides reasonable defaults (minimally obtrusive)

  • Has actually had impact
    • Originally available for Linux (2.2)
    • Now ships with FreeBSD
    • Windows introduced similar Mandatory Integrity Control (MIC)

CS446/646 C. Papachristos

29 of 37

LOMAC

 

CS446/646 C. Papachristos

30 of 37

LOMAC

LOMAC Defaults

  • Two Integrity Levels: 1 and 2

  • Level 2 (High-Integrity) contains:
    • FreeBSD/Linux Files intact from distro, static Web Server config
    • The console, Trusted terminals, Trusted Network

  • Level 1 (Low-Integrity) contains:
    • NICs connected to Internet, Untrusted terminals, etc.

  • Idea: Suppose Worm compromises your Web Server
    • Worm comes from external Network → Level 1
    • Won’t be able to muck with System Files or Web Server config

CS446/646 C. Papachristos

Note: Can-Flow-To is downward;

opposite of earlier diagram

31 of 37

LOMAC

 

CS446/646 C. Papachristos

32 of 37

LOMAC

 

CS446/646 C. Papachristos

33 of 37

LOMAC

 

CS446/646 C. Papachristos

34 of 37

LOMAC

 

CS446/646 C. Papachristos

35 of 37

LOMAC

 

CS446/646 C. Papachristos

36 of 37

LOMAC

 

CS446/646 C. Papachristos

37 of 37

Time for Questions !

CS-446/646

CS446/646 C. Papachristos