首页> 外文会议>2011 Network and distributed system security symposium >SigGraph: Brute Force Scanning of Kernel Data Structure Instances Using Graph-based Signatures
【24h】

SigGraph: Brute Force Scanning of Kernel Data Structure Instances Using Graph-based Signatures

机译:SigGraph:使用基于图的签名对内核数据结构实例进行蛮力扫描

获取原文
获取原文并翻译 | 示例

摘要

Brute force scanning of kernel memory images for finding kernel data structure instances is an important function in many computer security and forensics applications. Brute force scanning requires effective, robust signatures of kernel data structures. Existing approaches often use the value invariants of certain fields as data structure signatures. However, they do not fully exploit the rich points-to relations between kernel data structures. In this paper, we show that such points-to relations can be leveraged to generate graph-based structural invariant signatures. More specifically, we develop SigGraph, a framework that systematically generates non-isomorphic signatures for data structures in an OS kernel. Each signature is a graph rooted at a subject data structure with its edges reflecting the points-to relations with other data structures. Our experiments with a range of Linux kernels show that SigGraph-based signatures achieve high accuracy in recognizing kernel data structure instances via brute force scanning. We further show that SigGraph achieves better robustness against pointer value anomalies and corruptions, without requiring global memory mapping and object reachability. We demonstrate that SigGraph can be applied to kernel memory forensics, kernel rootkit detection, and kernel version inference.
机译:在许多计算机安全和取证应用程序中,蛮力扫描内核内存映像以查找内核数据结构实例是一项重要功能。蛮力扫描需要有效,强大的内核数据结构签名。现有方法通常将某些字段的值不变量用作数据结构签名。但是,它们没有充分利用内核数据结构之间的丰富点对关系。在本文中,我们表明可以利用这种点对点关系来生成基于图的结构不变签名。更具体地说,我们开发了SigGraph,这是一个系统地为OS内核中的数据结构生成非同构签名的框架。每个签名都是植根于主题数据结构的图形,其边缘反映了与其他数据结构的指向关系。我们在一系列Linux内核上进行的实验表明,基于SigGraph的签名在通过暴力扫描识别内核数据结构实例时实现了高精度。我们进一步表明,SigGraph在不需要全局内存映射和对象可访问性的情况下,可以更好地抵抗指针值异常和损坏。我们证明了SigGraph可以应用于内核内存取证,内核rootkit检测和内核版本推断。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号