首页> 外文期刊>IEEE transactions on dependable and secure computing >KI-Mon ARM: A Hardware-Assisted Event-triggered Monitoring Platform for Mutable Kernel Object
【24h】

KI-Mon ARM: A Hardware-Assisted Event-triggered Monitoring Platform for Mutable Kernel Object

机译:KI-Mon ARM:可变内核对象的硬件辅助事件触发监视平台

获取原文
获取原文并翻译 | 示例

摘要

External hardware-based kernel integrity monitors have been proposed to mitigate kernel-level malwares. However, the existing external approaches have been limited to monitoring the static regions of kernel while the latest rootkits manipulate the dynamic kernel objects. To address the issue, we present KI-Mon, a hardware-based platform that introduces event-triggered monitoring techniques for kernel dynamic objects. KI-Mon advances the bus traffic snooping technique to not only detect memory write traffic on the host bus but also filter out all but meaningful traffic to generate events. We show how kernel invariant verification software can be developed around these events, and also provide a set of APIs for additional invariant verification development. We also report our findings and considerations on the unique challenges for external monitors - such as cache coherency, dynamic object tracing. We introduce host-side kernel changes that alleviate these issues that involve changes in kernel's object allocation and cache policy control. We have built a prototype of KI-Mon on the ARM architecture to demonstrate the efficacy of KI-Mon's event-triggered mechanism in terms of performance overhead for the monitored host system and the processor usage of the KI-Mon processor.
机译:已经提出了基于外部硬件的内核完整性监视器来缓解内核级恶意软件。但是,现有的外部方法仅限于监视内核的静态区域,而最新的rootkit却可以处理动态的内核对象。为了解决这个问题,我们介绍了KI-Mon,这是一个基于硬件的平台,它引入了事件触发的内核动态对象监视技术。 KI-Mon改进了总线流量侦听技术,不仅可以检测主机总线上的内存写流量,还可以过滤掉所有有意义的流量以生成事件。我们展示了如何围绕这些事件开发内核不变验证软件,并且还提供了一组用于其他不变验证开发的API。我们还报告了有关外部监视器所面临的独特挑战的发现和考虑因素,例如缓存一致性,动态对象跟踪。我们介绍了主机端内核更改,以缓解涉及内核对象分配和缓存策略控制更改的这些问题。我们已经在ARM体系结构上构建了KI-Mon的原型,以证明KI-Mon事件触发机制在受监控主机系统的性能开销和KI-Mon处理器的处理器使用方面的功效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号