Global ETD Search
Search theses and dissertations gathered from participating repositories worldwide. Every result links back to the library that holds it. No account is needed.
Results
Showing 1 to 20 of 34 for “"system call"”.
-
Acetone : a system call interface for Asbestos labels
Acetone is a secure operating system kernel that uses a shared address space and supports Asbestos labels. Acetone uses Asbestos labels to enable a wide variety of security policies including ones that prevent untrusted applications from being able to disclose private data. All threads run in the …
-
The Triple Pot and techniques in distributed system call intrusion detection
… engineers need to devise ways to protect their systems from hackers. One of the ways that they do this is through intrusion detection. Host based intrusion detection systems reside on the computer and perform internal diagnostics of a computer to detect malware and misuse. These HIDS use a …
-
Improving security at the system-call boundary in a type-safe operating system
Historically, most approaches to operating sytems security aim to either protect the kernel (e.g., the MMU) or protect user applications (e.g., W [symbol] X). However, little study has been done into protecting the boundary between these layers. We describe a vulnerability in Tock, a type-safe …
-
Practical Exploit Mitigation Design Against Code Re-Use and System Call Abuse Attacks
… with new exploit mitigation designs. More specifically though, defenses have had to correspondingly extend their capabilities to protect more aspects of code, leading to defense techniques becoming increasingly complex. Trouble then arises as supporting such fine-grained defenses brings inherent …
-
Verifying an I/O-concurrent file system
Systems software is a good target for verification due to its prevalent usage and its complexity, which can lead to tricky bugs that are hard to test for. One source of complexity in systems software is concurrency, but thus far verification techniques have struggled to enable large-scale …
-
Windows security sandbox framework
<p>"Software systems are vulnerable to attack in many different ways. Systems can be poorly implemented which could allow an attacker access to the system through legitimate means such as anonymous access to a server or security controls and access lists can be configured incorrectly which would …
-
The role of long duration energy storage in decarbonizing power systems
Plans for a decarbonized power system call for a significant increase in generation from variable renewable energy (VRE) sources, i.e. wind and solar. Yet, the intermittency of these resources introduces new challenges in operating the grid, including the need for sufficient operating flexibility …
-
A file server for the DistriX prototype : a multitransputer UNIX system
The DISTRIX operating system is a multiprocessor distributed operating system based on UNIX. It consists of a number of satellite processors connected to central servers. The system is derived from the MINIX operating system, compatible with UNIX Version 7. A remote procedure call interface is used …
-
Compiling Gallina to go for the FSCQ file system
Over the last decade, systems software verification has become increasingly practical. Many verified systems have been written in the language of a proof assistant, proved correct, and then made runnable using code extraction. However, due to the rigidity of extraction and the overhead of the …
-
Space Use and Survival of White-Tailed Deer in a Disturbance-Driven System Containing a Restored Apex Predator
… concolor coryi), their primary predator in this system, call for a renewed look at how these forces affect this deer herd. To assess the effects of these forces on seasonal space use, behavior, and survival of deer, I analyzed GPS telemetry and camera trap data, highlighting the factors …
-
Interposing the Syscall Boundary: Transparent Python Execution in SigmaOS
… for tasks written, compiled, and statically linked in Golang and Rust, it currently lacks support for other languages, including interpreted ones like Python. To bridge this gap, this paper presents the first integration of an interpreted language into σOS, enabling native Python …
-
The benefits and costs of writing a POSIX Kernel in a high-level language
… memory, mmap, TCP/IP sockets, a logging file system, poll, etc.) to execute significant applications. Biscuit makes liberal use of Go's HLL features (closures, channels, maps, interfaces, garbage collected heap allocation), which subjectively made programming easier. The most challenging …
-
Integrating Multiple Data Views for Improved Malware Analysis
… take into account multiple views of malware. Typically, analysis has been performed in either the static domain (e.g. the byte information of the executable) or the dynamic domain (e.g. system call traces). This dissertation develops frameworks that can easily incorporate well-studied views from …
-
Monitoring and Preventing Data Exfiltration in Android-hosted Unmanned Aircraft System Applications
… are now being used to control unmanned aircraft systems (UAS) making smartphones the storehouse for all the data that is generated by the UAS. This data can be sensitive in nature which puts the user at the risk of data exfiltration. As most Android-hosted UAS applications are proprietary …
-
Behaviour-based classification of encryption-type ransomware using system calls
… threat in recent years, on the Android operating system. Many state-of-the-art anti-malware solutions have shifted away from static signature-based approaches as the techniques utilised by threat actors have become more advanced. Most newer solutions look towards the use of dynamic analysis to …
-
The scalable commutativity rule : designing scalable software for multicore processors
… are latent in software interfaces, such as system call APIs? Can scalability opportunities be identified even before any implementation exists, simply by considering interface specifications? To answer these questions this dissertation introduces the scalable commutativity rule: Whenever …
-
Design and Implementation of the VirtuOS Operating System
Most operating systems provide protection and isolation to user processes, but not to critical system components such as device drivers or other systems code. Consequently, failures in these components often lead to system failures. VirtuOS is an operating system that exploits a new method of …
-
Graphical Security Sandbox For Linux Systems
… application confinement mechanism for Linux systems in order to aid most users to increase their confidence in various applications that they stumble upon and use on a daily basis. Developed sandboxing facility monitors a targeted application’s activity and imposes restrictions on its access …
-
Rethinking computer architecture and operating system abstractions for good & evil
Computing systems are undergoing a radical shift, propelled by stern security requirements and an unprecedented growth in data and users. This change has proven to be abstraction breaking. Current hardware and Operating System (OS) abstractions were built at a time when we had minimal security …
Page 1 of 2