{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,3]],"date-time":"2026-04-03T15:49:11Z","timestamp":1775231351586,"version":"3.50.1"},"publisher-location":"Singapore","reference-count":29,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819691005","type":"print"},{"value":"9789819691012","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-981-96-9101-2_17","type":"book-chapter","created":{"date-parts":[[2025,7,10]],"date-time":"2025-07-10T09:42:11Z","timestamp":1752140531000},"page":"329-347","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Mitigating the\u00a0Unprivileged User Namespaces Based Privilege Escalation Attacks with\u00a0Linux Capabilities"],"prefix":"10.1007","author":[{"given":"Jingzi","family":"Meng","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuewu","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lingguang","family":"Lei","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chunjing","family":"Kou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peng","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Huawei","family":"Lu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,7,7]]},"reference":[{"key":"17_CR1","unstructured":"PrivGuard: protecting sensitive kernel data from privilege escalation attacks. IEEE J. Mag. (2018)"},{"key":"17_CR2","doi-asserted-by":"publisher","unstructured":"Akritidis, P., Cadar, C., Raiciu, C., Costa, M., Castro, M.: Preventing memory error exploits with WIT. In: 2008 IEEE Symposium on Security and Privacy (SP 2008), pp. 263\u2013277 (2008). https:\/\/doi.org\/10.1109\/SP.2008.30. ISSN: 2375-1207","DOI":"10.1109\/SP.2008.30"},{"key":"17_CR3","doi-asserted-by":"publisher","unstructured":"Canella, C., Schwarz, M., Haubenwallner, M., Schwarzl, M., Gruss, D.: Kaslr: break it, fix it, repeat. In: Proceedings of the 15th ACM Asia Conference on Computer and Communications Security, ASIA CCS 2020, pp. 481\u2013493. Association for Computing Machinery, New York (2020). https:\/\/doi.org\/10.1145\/3320269.3384747","DOI":"10.1145\/3320269.3384747"},{"key":"17_CR4","unstructured":"Cap_sys_admin: the new root (2012). https:\/\/lwn.net\/Articles\/486306\/"},{"key":"17_CR5","unstructured":"Castro, M., Costa, M., Harris, T.: Securing Software by Enforcing Data-flow Integrity (2006)"},{"key":"17_CR6","doi-asserted-by":"publisher","unstructured":"Chen, Q., Azab, A.M., Ganesh, G., Ning, P.: Privwatcher: non-bypassable monitoring and protection of process credentials from memory corruption attacks. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, ASIA CCS 2017, pp. 167\u2013178. Association for Computing Machinery, New York (2017). https:\/\/doi.org\/10.1145\/3052973.3053029","DOI":"10.1145\/3052973.3053029"},{"key":"17_CR7","unstructured":"CVE-2022-0492 (carpediem) explained (2020). https:\/\/www.hackthebox.com\/blog\/cve-2022-04920-carpe-diem-explained"},{"key":"17_CR8","unstructured":"Exploit database (2024). https:\/\/www.exploit-db.com\/"},{"key":"17_CR9","unstructured":"[RFC patch 00\/11] finer grained kernel address space randomization (2020). https:\/\/lwn.net\/ml\/linux-kernel\/20200205223950.1212394-1-kristen@linux.intel.com\/"},{"key":"17_CR10","unstructured":"Learnings from kCTF VRP\u2019s 42 Linux kernel exploits submissions (2023). https:\/\/security.googleblog.com\/2023\/06\/learnings-from-kctf-vrps-42-linux.html"},{"key":"17_CR11","doi-asserted-by":"publisher","unstructured":"Hasan, M.M., Ghavamnia, S., Polychronakis, M.: Decap: deprivileging programs by reducing their capabilities. In: Proceedings of the 25th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2022, pp. 395\u2013408. Association for Computing Machinery, New York (2022). https:\/\/doi.org\/10.1145\/3545948.3545978","DOI":"10.1145\/3545948.3545978"},{"key":"17_CR12","doi-asserted-by":"publisher","unstructured":"Kang, H., Kim, J., Shin, S.: MiniCon: automatic enforcement of a minimal capability set for security-enhanced containers. In: 2021 IEEE International IOT, Electronics and Mechatronics Conference (IEMTRONICS), pp.\u00a01\u20135 (2021). https:\/\/doi.org\/10.1109\/IEMTRONICS52119.2021.9422529","DOI":"10.1109\/IEMTRONICS52119.2021.9422529"},{"key":"17_CR13","doi-asserted-by":"publisher","unstructured":"Kuzuno, H., Yamauchi, T.: KDRM: kernel data relocation mechanism to mitigate privilege escalation attack. In: Li, S., Manulis, M., Miyaji, A. (eds.) Network and System Security, pp. 61\u201376. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-39828-5_4","DOI":"10.1007\/978-3-031-39828-5_4"},{"key":"17_CR14","doi-asserted-by":"publisher","unstructured":"Lin, X., Lei, L., Wang, Y., Jing, J., Sun, K., Zhou, Q.: A measurement study on linux container security: attacks and countermeasures. In: Proceedings of the 34th Annual Computer Security Applications Conference, ACSAC 2018, pp. 418\u2013429. Association for Computing Machinery, New York (2018). https:\/\/doi.org\/10.1145\/3274694.3274720. https:\/\/dl.acm.org\/doi\/10.1145\/3274694.3274720","DOI":"10.1145\/3274694.3274720"},{"key":"17_CR15","unstructured":"Linux kernel exploitation (2024). https:\/\/github.com\/xairy\/linux-kernel-exploitation?tab=readme-ov-file#lpe"},{"key":"17_CR16","unstructured":"Linux kernel (operating system): Product details, threats and statistics (2024). https:\/\/www.cvedetails.com\/product\/47\/Linux-Linux-Kernel.html?vendor_id=33"},{"key":"17_CR17","doi-asserted-by":"publisher","unstructured":"Maar, L., Schwarzl, M., Rauscher, F., Gruss, D., Mangard, S.: Dope: domain protection enforcement with PKS. In: Proceedings of the 39th Annual Computer Security Applications Conference, ACSAC 2023, pp. 662\u2013676. Association for Computing Machinery, New York (2023). https:\/\/doi.org\/10.1145\/3627106.3627113","DOI":"10.1145\/3627106.3627113"},{"key":"17_CR18","unstructured":"(2005). https:\/\/wiki.c2.com\/?PosixCapabilities"},{"key":"17_CR19","doi-asserted-by":"publisher","unstructured":"Proskurin, S., Momeu, M., Ghavamnia, S., Kemerlis, V.P., Polychronakis, M.: xMP: selective memory protection for kernel and user space. In: 2020 IEEE Symposium on Security and Privacy (SP), pp. 563\u2013577 (2020). https:\/\/doi.org\/10.1109\/SP40000.2020.00041. ISSN: 2375-1207","DOI":"10.1109\/SP40000.2020.00041"},{"key":"17_CR20","unstructured":"Rostedt, S., Oltmanns, E., Dunlap, R., Morton, A., Kacur, J., Teigland, D.: ftrace - function tracer (2017). https:\/\/www.kernel.org\/doc\/html\/v4.17\/trace\/ftrace.html"},{"key":"17_CR21","unstructured":"Smith, B., Grehan, R., Yager, T., Niemi, D.C., Voellm, A.F.: Byte-unixbench: a unix benchmark suite. Technical report (2011)"},{"key":"17_CR22","doi-asserted-by":"crossref","unstructured":"Song, C., Lee, B., Lu, K., Harris, W.R., Kim, T., Lee, W.: Enforcing Kernel Security Invariants with Data Flow Integrity. In: Proceedings of the 2016 Annual Network and Distributed System Security Symposium (NDSS), San Diego, CA (2016)","DOI":"10.14722\/ndss.2016.23218"},{"key":"17_CR23","doi-asserted-by":"crossref","unstructured":"Srivastava, A., Giffin, J.: Efficient protection of kernel data structures via object partitioning. In: Proceedings of the 28th Annual Computer Security Applications Conference, ACSAC 2012, pp. 429\u2013438. Association for Computing Machinery, New York (2012)","DOI":"10.1145\/2420950.2421012"},{"key":"17_CR24","doi-asserted-by":"publisher","unstructured":"Sun, M., Song, Z., Ren, X., Wu, D., Zhang, K.: LiCA: a fine-grained and path-sensitive linux capability analysis framework. In: Proceedings of the 25th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2022, pp. 364\u2013379. Association for Computing Machinery, New York (2022). https:\/\/doi.org\/10.1145\/3545948.3545966","DOI":"10.1145\/3545948.3545966"},{"key":"17_CR25","unstructured":"Restricted unprivileged user namespaces are coming to ubuntu 23.10 (2023). https:\/\/ubuntu.com\/blog\/ubuntu-23-10-restricted-unprivileged-user-namespaces"},{"key":"17_CR26","unstructured":"user_namespaces(7) \u2014 Linux manual page (2024). https:\/\/man7.org\/linux\/man-pages\/man7\/user_namespaces.7.html\/"},{"key":"17_CR27","doi-asserted-by":"publisher","unstructured":"Wei, L., Zuo, Y., Ding, Y., Dong, P., Huang, C., Gao, Y.: Security identifier randomization: a method to prevent kernel privilege-escalation attacks. In: 2016 30th International Conference on Advanced Information Networking and Applications Workshops (WAINA), pp. 838\u2013842 (2016). https:\/\/doi.org\/10.1109\/WAINA.2016.19","DOI":"10.1109\/WAINA.2016.19"},{"issue":"4","key":"17_CR28","doi-asserted-by":"publisher","first-page":"461","DOI":"10.1007\/s10207-020-00514-7","volume":"20","author":"T Yamauchi","year":"2020","unstructured":"Yamauchi, T., Akao, Y., Yoshitani, R., Nakamura, Y., Hashimoto, M.: Additional kernel observer: privilege escalation attack prevention mechanism focusing on system call privilege changes. Int. J. Inf. Secur. 20(4), 461\u2013473 (2020). https:\/\/doi.org\/10.1007\/s10207-020-00514-7","journal-title":"Int. J. Inf. Secur."},{"key":"17_CR29","doi-asserted-by":"publisher","unstructured":"Zhou, M., et al.: Container privilege escalation and escape detection method based on security-first architecture. In: 2023 IEEE International Conference on High Performance Computing & Communications, Data Science & Systems, Smart City & Dependability in Sensor, Cloud & Big Data Systems & Application (HPCC\/DSS\/SmartCity\/DependSys), pp. 490\u2013498 (2023). https:\/\/doi.org\/10.1109\/HPCC-DSS-SmartCity-DependSys60770.2023.00073","DOI":"10.1109\/HPCC-DSS-SmartCity-DependSys60770.2023.00073"}],"container-title":["Lecture Notes in Computer Science","Information Security and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-96-9101-2_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,3]],"date-time":"2026-04-03T14:56:07Z","timestamp":1775228167000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-96-9101-2_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9789819691005","9789819691012"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-981-96-9101-2_17","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"7 July 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ACISP","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australasian Conference on Information Security and Privacy","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Wollongong, NSW","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 July 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 July 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acisp2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/uow-ic2.github.io\/acisp2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}