Back to search

Freie Universität Berlin

Generation of Secure Runtime Environments for Untrusted Applications Through Machine Code Analysis

Abstract

dc:description.abstract

Infrastructure providers rely on the execution of third-party applications to offer their platforms to customers and researchers. The execution of each application without a preceded security review poses a risk for the system and the overall IT infrastructure. However, if the unreviewed application is available for execution, it is also available for an analysis to generate appropriate countermeasures to prevent unwanted behaviour. This work investigates the capabilities of an automated secure environment. This environment is generated based on the analysis of applications that are only available in their machine code format. The analysis focuses on the interaction of the application with the operating system through the system call interface. Therefore this work describes required technologies and mechanisms to collect data, process it and generate rules for a secure environment to protect assets from attacks. This process and the result environment is tested with real-world applications and attacks to determine its effectiveness and overall costs. It is shown that the described solution is able to decrease the rate of successful attacks against the system from 83% to 9% in selected use-cases. This is achieved with an execution overhead of 823 ms average. These results demonstrate that it is possible to utilise automatic software analysis pipelines to build restricted execution environments for pre-compiled applications. It also highlight the advantages and limitations of the selected approach to focus the analysis on the system call interface.

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Witt, Michael

Subjects

dc:subject × 7

Rights

Language dc:language
eng

Identifiers

dc:identifier.*

Chain of custody

source
Harvested from
Freie Universität Berlin
Base URL
refubium.fu-berlin.de/oai/request
Last updated
2026-08-21
Source record
OAI-PMH GetRecord
citation

Witt, Michael. Generation of Secure Runtime Environments for Untrusted Applications Through Machine Code Analysis. 2021. https://refubium.fu-berlin.de/handle/fub188/32513