首页> 外文会议>IEEE/IFIP International Conference on Embedded and Ubiquitous Computing >A Lightweight Detection and Recovery Infrastructure of Kernel Objects for Embedded Systems
【24h】

A Lightweight Detection and Recovery Infrastructure of Kernel Objects for Embedded Systems

机译:用于嵌入式系统的内核对象的轻量级检测和恢复基础架构

获取原文

摘要

The kernel objects consist of critical kernel data structures and system call functions, which are the most important data for a system, should be protected as first-class candidates. In this paper, a lightweight system-level detection and recovery infrastructure is presented for embedded systems. Inside the infrastructure, specific runtime protections have been implemented for different kernel objects, kernel data structures are protected by the periodic detection and recovery, the interception of arguments is used to protect vulnerable system calls. At runtime once any system inconsistency has been detected, predefined recovery actions will be invoked. The consistency detection regulations and corresponding recovery actions can also be flexibly customized by system developers. The infrastructure requires few modifications to kernel source code, thus it is easy to integrate into existing embedded systems. The evaluation experiment results indicate our prototype system can correctly detect the inconsistent kernel data structures caused by security attacks and also prevent kernel from exploits due to vulnerable system calls with acceptable penalty to system performance. Moreover, it is fully software-based without introducing any specific hardware and requires no modifications to system call APIs, therefore legacy commercial-off-the-shelf (COTS) applications can be also easily reused.
机译:内核对象由关键内核数据结构和系统调用函数组成,这是系统最重要的数据,应保护为一流的候选人。本文介绍了嵌入式系统的轻量级系统级检测和恢复基础设施。在基础架构内,已经为不同的内核对象实现了特定的运行时保护,通过定期检测和恢复来保护内核数据结构,参数拦截用于保护易受攻击的系统调用。在运行时检测到任何系统不一致后,将调用预定义的恢复操作。通过系统开发人员还可以灵活地定制了一致性检测规则和相应的恢复操作。基础架构需要对内核源代码的修改很少,因此很容易集成到现有的嵌入式系统中。评估实验结果表明我们的原型系统可以正确地检测由安全攻击引起的不一致的内核数据结构,并且还可以防止由于易受攻击的系统呼叫而导致的漏洞从漏洞利用到系统性能。此外,它是基于完全软件的,而不引入任何特定的硬件,并且不需要修改系统调用API,因此也可以容易地重复使用传统的商业现货(COTS)应用程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号