首页> 外文期刊>Computing and informatics >KERNEL CODE INTEGRITY PROTECTION BASED ON A VIRTUALIZED MEMORY ARCHITECTURE
【24h】

KERNEL CODE INTEGRITY PROTECTION BASED ON A VIRTUALIZED MEMORY ARCHITECTURE

机译:基于虚拟内存架构的内核代码完整性保护

获取原文
获取原文并翻译 | 示例

摘要

Kernel rootkits pose significant challenges on defensive techniques as they run at the highest privilege level along with the protection systems. Modern architectural approaches such as the NX protection have been used in mitigating attacks, however determined attackers can still bypass these defenses with specifically crafted payloads. In this paper, we propose a virtualized Harvard memory architecture to address the kernel code integrity problem, which virtually separates the code fetch and data access on the kernel code to prevent kernel from code modifications. We have implemented the proposed mechanism in commodity operating system, and the experimental results show that our approach is effective and incurs very low overhead.
机译:内核Rootkit与防护系统一起以最高特权级别运行,因此对防御技术提出了严峻挑战。诸如NX保护之类的现代体系结构方法已用于缓解攻击,但是坚定的攻击者仍然可以使用特制的有效载荷来绕过这些防御。在本文中,我们提出了一种虚拟化的哈佛内存架构来解决内核代码完整性问题,该问题实际上将代码获取与内核代码上的数据访问分开,以防止内核对代码进行修改。我们已经在商品操作系统中实现了所提出的机制,并且实验结果表明我们的方法是有效的并且产生非常低的开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号