# System call filtering

**URL:** <https://discuss.elastic.co/t/system-call-filtering/163155>\
**Category:** Elasticsearch\
**Created:** [January 7, 2019, 7:18am UTC](https://discuss.elastic.co/t/system-call-filtering/163155 "2019-01-07T07:18:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![li\_jessen2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/li_jessen2016/32/38817_2.png) [@li\_jessen2016](https://discuss.elastic.co/u/li_jessen2016)\
**Post date:** [January 7, 2019, 7:18am UTC](https://discuss.elastic.co/t/system-call-filtering/163155/1 "2019-01-07T07:18:58Z")

</div>

These system call filters are installed to prevent the ability to execute system calls related to forking as a defense mechanism against arbitrary code execution attacks on Elasticsearch .

What is "system calls related to forking" and why is it relevant for defense mechanism?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [January 7, 2019, 9:35am UTC](https://discuss.elastic.co/t/system-call-filtering/163155/2 "2019-01-07T09:35:45Z")

</div>

> [@li\_jessen2016](#):
>
> What is "system calls related to forking"

On Linux, the four filtered syscalls are `fork()`, `vfork()`, `execve()` and `execveat()`:

> <https://github.com/elastic/elasticsearch/blob/2b652f324240fc825f23210cffb3b73ecf9fb397/server/src/main/java/org/elasticsearch/bootstrap/SystemCallFilter.java#L377-L380>

> [@li\_jessen2016](#):
>
> why is it relevant for defense mechanism

Many remote code execution exploits work by executing a very small amount of code within the vulnerable process in order to start a separate process, normally a shell that's exposed to the network. This new process then allows much broader access to the rest of the system, opening the door to further vulnerabilities that are perhaps not remotely exploitable. If the syscalls that would be needed to start this separate process are blocked then this common exploit technique is not possible.

This is all somewhat theoretical right now since there are no known vulnerabilities, but Elasticsearch has these protections in place just in case one is discovered in the future.

---

<div class="post-metadata">

**Author:** ![li\_jessen2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/li_jessen2016/32/38817_2.png) [@li\_jessen2016](https://discuss.elastic.co/u/li_jessen2016)\
**Post date:** [January 7, 2019, 10:07am UTC](https://discuss.elastic.co/t/system-call-filtering/163155/3 "2019-01-07T10:07:16Z")

</div>

What does vulnerable process refer to in your reply? The Elasticsearch process?  
And how to execute a very small amount of code within the process remotely?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [January 7, 2019, 10:38am UTC](https://discuss.elastic.co/t/system-call-filtering/163155/4 "2019-01-07T10:38:57Z")

</div>

> [@li\_jessen2016](#):
>
> What does vulnerable process refer to in your reply? The Elasticsearch process?

What I said applies to syscall filters in general, and was not specifically about Elasticsearch. However, the syscall filters _in Elasticsearch_ are there to protect the Elasticsearch process.

> [@li\_jessen2016](#):
>
> And how to execute a very small amount of code within the process remotely?

There is no known way to do this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 4, 2019, 10:39am UTC](https://discuss.elastic.co/t/system-call-filtering/163155/5 "2019-02-04T10:39:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
