首页> 外文期刊>Computers & Security >A kernel stack protection model against attacks from kernel execution units
【24h】

A kernel stack protection model against attacks from kernel execution units

机译:防止来自内核执行单元攻击的内核堆栈保护模型

获取原文
获取原文并翻译 | 示例

摘要

Many defensive approaches have been proposed to protect the integrity of the operating system kernel stack. However, some types of attacks, such as the "retum-to-schedule" rootkit, pose a serious threat to these approaches. In this paper, we present a kernel stack protection model to protect the integrity of the kernel stack. It adopts a synchronous design strategy to bind the execution unit with its kernel stack using virtualization technology, and allows the execution unit to write its own current kernel stack with legal kernel codes. To test the model, we propose three kinds of potential attacks which extend the "retum-to-schedule" rootkit. The experimental results show that the prototype of the model can be effective against all attack methods, and introduces a performance cost of only 2%. Therefore, it effectively protects all types of data on the kernel stack with a small performance overhead.
机译:已经提出了许多防御方法来保护操作系统内核堆栈的完整性。但是,某些类型的攻击,例如“按期执行” rootkit,对这些方法构成了严重威胁。在本文中,我们提出了一个内核堆栈保护模型来保护内核堆栈的完整性。它采用同步设计策略,使用虚拟化技术将执行单元与其内核堆栈绑定在一起,并允许执行单元使用合法的内核代码编写自己的当前内核堆栈。为了测试该模型,我们提出了三种潜在的攻击,这些攻击扩展了“按计划执行” rootkit。实验结果表明,该模型的原型可以有效地抵御所有攻击方法,并且性能成本仅为2%。因此,它以很小的性能开销有效地保护了内核堆栈上的所有类型的数据。

著录项

  • 来源
    《Computers & Security》 |2018年第1期|96-106|共11页
  • 作者单位

    Information System & Security and Countermeasures Experiments Center, Beijing Institute of Technology, Beijing 100081, PR China;

    Information System & Security and Countermeasures Experiments Center, Beijing Institute of Technology, Beijing 100081, PR China;

    Information System & Security and Countermeasures Experiments Center, Beijing Institute of Technology, Beijing 100081, PR China;

    Information System & Security and Countermeasures Experiments Center, Beijing Institute of Technology, Beijing 100081, PR China;

    Information System & Security and Countermeasures Experiments Center, Beijing Institute of Technology, Beijing 100081, PR China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Virtualization; Rootkit detection; Control flow integrity; Kernel stack integrity; Ret-to-sched rootkit;

    机译:虚拟化;Rootkit检测;控制流程的完整性;内核堆栈完整性;预定的Rootkit;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号