首页> 外文会议>Iranian Conference on Electrical Engineering >KLrtD: Kernel level rootkit detection
【24h】

KLrtD: Kernel level rootkit detection

机译:KLrtD:内核级别的rootkit检测

获取原文

摘要

Kernel rootkits pose a significant threat to computer systems as they run at the highest privilege level of operating system and have unrestricted access to the resources of their victims. Majority of current efforts in kernel rootkit defense focus on the detection of kernel rootkits. Various untrusted extensions, it remains a challenging problem to comprehensively preserve the integrity of OS kernels in a practical and generic way. In this regard, we propose a detection method named WHKrD that blocks and detects data kernel rootkit attacks by monitoring kernel data access using virtual machine monitor (VMM). WHKrD in inference mode, observe the execution of the kernel during an inference phase and extract white list rules on kernel data structures. In the following, integrity checker phase uses these rules as specifications of data structure integrity and any violation of rules indicates an infection. We have implemented a prototype of our system using the xen VMM. Our experiments show that it successfully detects data kernel rootkits, demonstrating its effectiveness and practicality.
机译:内核Rootkit在计算机系统上以操作系统的最高特权级别运行,并且对受害者资源的访问不受限制,因此对计算机系统构成了重大威胁。当前在内核rootkit防御方面的大部分工作都集中在内核rootkit的检测上。各种不受信任的扩展,以实用且通用的方式全面保留OS内核的完整性仍然是一个具有挑战性的问题。在这方面,我们提出了一种名为WHKrD的检测方法,该方法通过使用虚拟机监视器(VMM)监视内核数据访问来阻止和检测数据内核rootkit攻击。 WHKrD在推理模式下,在推理阶段观察内核的执行情况,并提取内核数据结构上的白名单规则。下面,完整性检查程序阶段将这些规则用作数据结构完整性的规范,并且任何违反规则的行为都表明存在感染。我们已经使用xen VMM实现了系统的原型。我们的实验表明,它成功检测了数据内核rootkit,证明了其有效性和实用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号