Computer Science ›› 2026, Vol. 53 ›› Issue (8): 446-454.doi: 10.11896/jsjkx.250600180

• Computer Software • Previous Articles     Next Articles

Program Capabilities Reduction Based on Code Specialization

FAN Yuhao1, SUN Cong1, ZHANG Linmao2   

  1. 1 School of Cyber Engineering, Xidian University, Xi’an 710126, China
    2 Huawei Technologies Co., Ltd., Xi’an 710100, China
  • Received:2025-06-24 Revised:2025-11-06 Published:2026-08-17
  • About author:FAN Yuhao,born in 2000,master.His main research interests include software security and so on.
    SUN Cong,born in 1982,Ph.D,professor,Ph.D supervisor,is a member of CCF(No.28286M).His main research interests include software security,program analysis,and high-confidence software.
  • Supported by:
    National Natural Science Foundation of China(62272366).

Abstract: The setuid mechanism in Linux enables users to temporarily escalate the privileges of programs.Such a mechanism violates the principle of least privilege.Once vulnerabilities exist in these programs,attackers can exploit the privileges to conduct privilege escalation,resulting in severe consequences.To address this issue,the capability mechanism in Linux decomposes the root privilege into a set of fine-grained capabilities and assigns only the required capability to the program,thereby mitigating risks.Existing capability-limiting approaches based on system-call identification have exhibited drawbacks when obtaining the genuine capability subset required by the program.On one hand,due to the failure to filter out redundant code in dynamic libraries and the inaccurate analysis of the Glibc call graph,the resulting system-call set is over-approximated.On the other hand,the inaccurate system-call parameter analysis leads to a conservative estimation of capabilities for the system calls.This paper presents a program capability-limiting framework based on code specialization.The program-dependent dynamic libraries are pruned to reduce the impact of redundant library code on the system-call identification.Combined with the dynamic library pruning results,this work analyzes the system calls on the pruned Glibc call graph and obtains a more precise set of system calls specific to the program.Moreover,this work conducts iterative backward data-flow analysis on the pruned program-specific dynamic libraries to extract sensitive parameter values for specific system calls.Based on the program-specific system call set and the sensitive para-meter values,the accurate capability set required by the program is identified.For a specific binary program,the proposed framework conducts the analysis and restricts the program with the accurate capability set and system-call set,thereby reducing the privileged operations that the program can perform.Experimental results demonstrate that,compared to state-of-the-art approaches,the proposed approach identifies system calls more accurately and enforces stronger capability restrictions on the program.On setuid programs,this work can significantly reduce the attack surface and alleviate privilege-escalation vulnerabilities.

Key words: Privilege, System call, Linux capability, Program analysis, Data-flow analysis, Parameter analysis

CLC Number: 

  • TP309
[1] GREGG B.Linux bcc Tracing Security Capabilities[EB/OL].(2016-10-01)[2025-05-17].https://www.brendangregg.com/blog/2016-10-01/linux-bcc-security-capabilities.html.
[2] KANG H,KIM J,SHIN S.MiniCon:Automatic Enforcement of a Minimal Capability Set for Security-Enhanced Containers[C]//Proceedings of the IEEE International IoT,Electronics and Mechatronics Conference.IEEE,2021:1-5.
[3] HASAN M M,GHAVAMNIA S,POLYCHRONAKIS M.Decap:Deprivileging Programs by Reducing Their Capabilities[C]//Proceedings of the 25th International Symposium on Research in Attacks,Intrusions and Defenses.ACM,2022:395-408.
[4] DEMARINIS N,WILLIAMS-KING K,JIN D,et al.Sysfilter:Automated System Call Filtering for Commodity Software[C]//Proceedings of the 23rd International Symposium on Research in Attacks,Intrusions and Defenses.ACM,2020:459-474.
[5] GHAVAMNIA S,PALIT T,BENAMEUR A,et al.Confine:Automated System Call Policy Generation for Container Attack Surface Reduction[C]//Proceedings of the 23rd International Symposium on Research in Attacks,Intrusions and Defenses.ACM,2020:443-458.
[6] KERRISK M.CAP_SYS_ADMIN:the new root[EB/OL].(2012-02-15)[2025-05-17].https://lwn.net/Articles/486306/.
[7] ZHANG L M,SUN C,RAO X.Dynamic Library Debloating Enhanced System Call Restriction of Programs[J].Computer Science,2025,52(7):50-57.
[8] GHAVAMNIA S,PALIT T,MISHRA S,et al.Temporal System Call Specialization for Attack Surface Reduction[C]//Proceedings of the 29th USENIX Security Symposium.USENIX Association,2020:1749-1766.
[9] RAJAGOPALAN V L,KLEFTOGIORGOS K,GOKTAS E,et al.SysPart:Automated Temporal System Call Filtering for Binaries[C]//Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security.ACM,2023:1979-1993.
[10] GAIDIS A J,ATLIDAKIS V,KEMERLIS V P.SysXCHG:Refining Privilege with Adaptive System Call Filters[C]//Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security.ACM,2023:1964-1978.
[11] Musl Libc[EB/OL].2024[2025-05-17].https://musl.libc.org/.
[12] HU X Y,ZHOU J,GRAVANI S,et al.Transforming Code to Drop Dead Privileges[C]//Proceedings of the 2018 IEEE Cybersecurity Development.IEEE,2018:45-52.
[13] SUN M H,SONG Z R,REN XX,et al.LiCA:A Fine-Grained and Path-Sensitive Linux Capability Analysis Framework[C]//Proceedings of the 25th International Symposium on Research in Attacks,Intrusions and Defenses.2022:364-379.
[14] VAN DER VEEN V,GOKTAS E,CONTAG M,et al.A Tough Call:Mitigating Advanced Code-Reuse Attacks at the Binary Level[C]//Proceedings of 2016 IEEE Symposium on Security and Privacy.IEEE,2016:934-953.
[15] ANDERSEN L O.Program analysis and specialization for the C programming language[D].Copenhagen:University of Cophenhagen,1994.
[16] HIND M.Pointer Analysis:Haven’t We Solved This ProblemYet?[C]//Proceedings of the ACM SIGPLAN/SIGSOFT Workshop on Program Analysis for Software Tools and Engineering.ACM,2001:54-61.
[17] SUI Y L,XUE J L.SVF:Interprocedural Static Value-Flow Analysis in LLVM[C]//Proceedings of the 25th International Conference on Compiler Construction.ACM,2016:265-266.
[18] LUK C K,COHN R,MUTH R,et al.Pin:Building Customized Program Analysis Tools with Dynamic Instrumentation[J].ACM SIGPLAN Notices,2005,40(6):190-200.
[1] CHEN Shanshan, JING Ningkang. OptimalFix:Complete Framework for Efficient Detection and Patch of Vulnerabilities in SmartContracts Automatically [J]. Computer Science, 2026, 53(7): 422-432.
[2] ZHANG Linmao, SUN Cong, RAO Xue. Dynamic Library Debloating Enhanced System Call Restriction of Programs [J]. Computer Science, 2025, 52(7): 50-57.
[3] FAN Yi, HU Tao, YI Peng. Host Anomaly Detection Framework Based on Multifaceted Information Fusion of SemanticFeatures for System Calls [J]. Computer Science, 2024, 51(7): 380-388.
[4] DING Duo, SUN Cong, ZHENG Tao. Robust Binary Program Debloating [J]. Computer Science, 2024, 51(10): 208-217.
[5] FAN Yi, HU Tao, YI Peng. System Call Host Intrusion Detection Technology Based on Generative Adversarial Network [J]. Computer Science, 2024, 51(10): 408-415.
[6] JIN Tiancheng, DOU Liang, ZHANG Wei, XIAO Chunyun, LIU Feng, ZHOU Aimin. OJ Exercise Recommendation Model Based on Deep Reinforcement Learning and Program Analysis [J]. Computer Science, 2023, 50(8): 58-67.
[7] JIANG Cheng-man, HUA Bao-jian, FAN Qi-liang, ZHU Hong-jun, XU Bo, PAN Zhi-zhong. Empirical Security Study of Native Code in Python Virtual Machines [J]. Computer Science, 2022, 49(6A): 474-479.
[8] WEI Hui, CHEN Ze-mao, ZHANG Li-qiang. Anomaly Detection Framework of System Call Trace Based on Sequence and Frequency Patterns [J]. Computer Science, 2022, 49(6): 350-355.
[9] LIU Pei-wen, SHU Hui, LYU Xiao-shao, ZHAO Yun-tian. Automatic Analysis Technology of Kernel Vulnerability Attack Based on Finite State Machine [J]. Computer Science, 2022, 49(11): 326-334.
[10] BAI Wei, PAN Zhi-song, XIA Shi-ming, CHENG Ang-xuan. Network Security Configuration Generation Framework Based on Genetic Algorithm Optimization [J]. Computer Science, 2020, 47(5): 306-312.
[11] LI Hao, ZHONG Sheng, KANG Yan, LI Tao, ZHANG Ya-chuan, BU Rong-jing. API Recommendation Model with Fusion Domain Knowledge [J]. Computer Science, 2020, 47(11A): 544-548.
[12] CAI Yan-guang, CHEN Hou-ren, QI Yuan-hang. Chaotic Fireworks Algorithm for Solving Travelling Salesman Problem [J]. Computer Science, 2019, 46(6A): 85-88.
[13] YIN Zhong-xu, ZHANG Lian-cheng. SQL Injection Intrusion Avoidance Scheme Based on Automatic Insertion of Dataflow-relevant Filters [J]. Computer Science, 2019, 46(1): 201-205.
[14] DONG Jia-xing and XU Chang. Efficient Clone Detection Technique for Functionally Similar Programs [J]. Computer Science, 2017, 44(4): 12-15.
[15] LIU Yan-na, CHEN Li and TANG Sheng-lin. Error Checking Tool for DAG-based Task Parallel Programs [J]. Computer Science, 2017, 44(3): 38-41.
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!