문서화되지 않은 macOS 인터페이스 식별을 통한 퍼블릭 프레임워크-XPC 서비스 의존성 그래프 생성 및 공격 표면 분석

Constructing a Public Framework-XPC Service Dependency Graph via Undocumented macOS Interface Identification for Attack Surface Analysis
  • 이동하
  • 강민주
  • 한규상
  • 박정우
  • 전승호

초록

macOS consists of multi-layered components including public and private frameworks and XPC services. Private frameworks are distributed without official documentation or headers, leaving a substantial portion of the interfaces exposed in the actual system outside the scope of the SDK (Software Development Kit). Such undocumented interfaces represent realistic attack targets that adversaries can exploit. However, existing attack surface analysis research has focused on single-layer interfaces such as system calls and IOKit, failing to sufficiently identify hidden attack surfaces. To address this, the present study proposes a dependency graph construction approach that integrates XPC service and endpoint identification, static and dynamic framework dependency analysis, and ObjC metadata analysis to trace paths from public frameworks through private frameworks to XPC services, and quantitatively validates the methodology against a dataset of 2,918 binaries.

키워드

macOSAttack SurfaceUndocumented InterfacePrivate FrameworkXPC Service
제목
문서화되지 않은 macOS 인터페이스 식별을 통한 퍼블릭 프레임워크-XPC 서비스 의존성 그래프 생성 및 공격 표면 분석
제목 (타언어)
Constructing a Public Framework-XPC Service Dependency Graph via Undocumented macOS Interface Identification for Attack Surface Analysis
저자
이동하강민주한규상박정우전승호
DOI
10.13089/JKIISC.2026.36.3.857
발행일
2026-06
유형
Y
저널명
정보보호학회논문지
36
3
페이지
857 ~ 868