OAMAC: Origin-Aware Mandatory Access Control for Practical Post-Compromise Attack Surface Reduction
Modern operating systems provide powerful mandatory access control mechanisms, yet they largely reason about who executes code rather than how execution originates. As a result, processes launched remotely, locally, or by background services are often treated equivalently once privileges are obtained, complicating security reasoning...