论文标题
文件系统中的安全战:从脆弱性的角度来看的实证研究
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
论文作者
论文摘要
本文遵循以漏洞为中心的观点,介绍了现代文件系统安全性的系统研究。具体而言,我们在过去20年中收集了377个文件系统漏洞。我们从四个维度来表征它们,包括漏洞出现,如何利用漏洞,会产生什么后果以及如何固定漏洞的原因。这样,我们深入了解文件系统面临的攻击表面,攻击表面施加的威胁以及减轻文件系统中攻击的好与坏实践。我们设想,我们的研究将为文件系统的未来开发,提高文件系统安全性以及相关漏洞缓解解决方案带来见解。
This paper presents a systematic study on the security of modern file systems, following a vulnerability-centric perspective. Specifically, we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years. We characterize them from four dimensions that include why the vulnerabilities appear, how the vulnerabilities can be exploited, what consequences can arise, and how the vulnerabilities are fixed. This way, we build a deep understanding of the attack surfaces faced by file systems, the threats imposed by the attack surfaces, and the good and bad practices in mitigating the attacks in file systems. We envision that our study will bring insights towards the future development of file systems, the enhancement of file system security, and the relevant vulnerability mitigating solutions.