## Basics - Task OS security: Protect data and processes - *What is a secure OS?* - Provide security mechanisms - Ensure that security goals are enforced - *‌Access enforcement satisfies the reference monitor concept* (otherwise, not secure systems exist) - Usually, refers to *security kernel* - Goals: - Make it hard for an adversary from system software perspective - Make it harder to distribute bad code - Make it harder to turn good code bad - Security goals: - *Secrecy* (focus on read operations) - *Integrity* (focus on write operations) - *Availability* (focus on consumption of resources) - Focus: Secrecy + Integrity (availability still affects them) - Important: **Trade-off function and security** ### Motivation - Current OS security - Conventional OS security methods are insufficient - Conventional mechanisms enforce protection (see Access Matrix) - Adversary gets user access rights - Conditions for vulnerability: - Flaw in code - Accessible to adversary - Capability of adversary to exploit flaw - Example: - Flaw: Buffer overflow - Accessible: User input is read into buffer - Capability of exploitation: Adversary injects malicious code - Attacks: - Adversary-controlled code (e.g., virus, trojan horse) - Confused deputy attack (privileged program is tricked into misusing its authority, e.g., privilege escalation, SQL Injection, TOCTTOU) - Return-oriented attack (e.g., Return-to-libc) - Problem: - Adversary has a lot ways to inject malicious code - Intrusion detection is hard - Defenses: - Run approved code (e.g., integrity) - Sandbox code - System integrity protection (i.e., protect against malicious root user) - Responsible for security: - Programmers - OS Distributors - Administrators - Users - Service Providers - Content Providers ### Definitions - *Process secrecy* - Do not communicate with unauthorized parties - *Process integrity* - Behavior as specified - Code not changed - Do not depend on adversary's input - *Trusted Computing Base* - Set of components which is considered trustworthy - If a vulnerability in the TCB occurs, the security of the complete system is in danger - Contains security policy - *Protection* - Keeps secrecy and integrity for **benign** processes - Results in safety (errors from non-malicious entities) - Protection is incapable of defending against an active/determined adversary - *Security* - Keep secrecy and integrity for potentially malicious processes - Process should not communicate with unauthorized parties - Ensure Security Goals (CIA)