Got Root? A Linux Priv-Esc Benchmark
Andreas Happe, J\"urgen Cito

TL;DR
This paper introduces a comprehensive benchmark for evaluating Linux privilege escalation techniques, aiding security assessments by comparing human and automated attack methods to improve system defenses.
Contribution
It presents a standardized platform for assessing and comparing privilege escalation methods, addressing a critical gap in Linux security evaluation.
Findings
Benchmark enables consistent evaluation of privilege escalation techniques
Facilitates comparison between human and automated attacks
Helps improve Linux system security defenses
Abstract
Linux systems are integral to the infrastructure of modern computing environments, necessitating robust security measures to prevent unauthorized access. Privilege escalation attacks represent a significant threat, typically allowing attackers to elevate their privileges from an initial low-privilege account to the all-powerful root account. A benchmark set of vulnerable systems is of high importance to evaluate the effectiveness of privilege-escalation techniques performed by both humans and automated tooling. Analyzing their behavior allows defenders to better fortify their entrusted Linux systems and thus protect their infrastructure from potentially devastating attacks. To address this gap, we developed a comprehensive benchmark for Linux privilege escalation. It provides a standardized platform to evaluate and compare the performance of human and synthetic actors, e.g., hacking…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Data Storage Technologies · Distributed and Parallel Computing Systems · Peer-to-Peer Network Technologies
