首页> 中文期刊>中国通信 >Detecting Compromised Kernel Hooks with Support of Hardware Debugging Features

Detecting Compromised Kernel Hooks with Support of Hardware Debugging Features

     

摘要

Although there exist a few good schemes to protect the kernel hooks of operating systems, attackers are still able to circumvent existing defense mechanisms with spurious context information. To address this challenge, this paper proposes a framework, called HookIMA, to detect compromised kernel hooks by using hardware debugging features. The key contribution of the work is that context information is captured from hardware instead of from relatively vulnerable kernel data. Using commodity hardware, a proof-of-concept prototype system of HookIMA has been developed. This prototype handles 3 082 dynamic control-flow transfers with related hooks in the kernel space. Experiments show that HookIMA is capable of detecting compromised kernel hooks caused by kernel rootkits. Performance evaluations with UnixBench indicate that runtime overhead introduced by HookIMA is about 21.5%.

著录项

  • 来源
    《中国通信》|2012年第10期|78-90|共13页
  • 作者单位

    School of Information, Renmin University of China, Beijing 100872, P.R.China;

    Key Laboratory of Data Engineering and Knowledge Engineering of Ministry of Education, Renmin University of China,Beijing 100872, P.R.China;

    School of Information, Renmin University of China, Beijing 100872, P.R.China;

    Key Laboratory of Data Engineering and Knowledge Engineering of Ministry of Education, Renmin University of China,Beijing 100872, P.R.China;

    Information Engineering University of China, Zhengzhou 450004, P.R.China;

    Information Engineering University of China, Zhengzhou 450004, P.R.China;

    School of Information, Renmin University of China, Beijing 100872, P.R.China;

    Key Laboratory of Data Engineering and Knowledge Engineering of Ministry of Education, Renmin University of China,Beijing 100872, P.R.China;

  • 原文格式 PDF
  • 正文语种 chi
  • 中图分类
  • 关键词

  • 入库时间 2023-07-25 20:36:43

相似文献

  • 中文文献
  • 外文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号