Containing a Confused Deputy on x86: A Survey of Privilege Escalation Mitigation Techniques

  • Brookes S
  • Taylor S
N/ACitations
Citations of this article
6Readers
Mendeley users who have this article in their library.

Abstract

The weak separation between user-and kernel-space in modern operating systems facilitates several forms of privilege escalation. This paper provides a survey of protection techniques, both cutting-edge and time-tested, used to prevent common privilege escalation attacks. The techniques are compared against each other in terms of their effectiveness, their performance impact, the complexity of their implementation, and their impact on diversification techniques such as ASLR. Overall the literature provides a litany of disjoint techniques, each of which trades some performance cost for effectiveness against a particular isolated threat. No single technique was found to effectively mitigate all known and potential attack vectors with reasonable performance cost overhead.

Cite

CITATION STYLE

APA

Brookes, S., & Taylor, S. (2016). Containing a Confused Deputy on x86: A Survey of Privilege Escalation Mitigation Techniques. International Journal of Advanced Computer Science and Applications, 7(4). https://doi.org/10.14569/ijacsa.2016.070463

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free