首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >Enforcing Mandatory Access Control in Commodity OS to Disable Malware
【24h】

Enforcing Mandatory Access Control in Commodity OS to Disable Malware

机译:在商品操作系统中强制执行强制访问控制以禁用恶意软件

获取原文
获取原文并翻译 | 示例

摘要

Enforcing a practical Mandatory Access Control (MAC) in a commercial operating system to tackle malware problem is a grand challenge but also a promising approach. The firmest barriers to apply MAC to defeat malware programs are the incompatible and unusable problems in existing MAC systems. To address these issues, we manually analyze 2,600 malware samples one by one and two types of MAC enforced operating systems, and then design a novel MAC enforcement approach, named Tracer, which incorporates intrusion detection and tracing in a commercial operating system. The approach conceptually consists of three actions: detecting, tracing, and restricting suspected intruders. One novelty is that it leverages light-weight intrusion detection and tracing techniques to automate security label configuration that is widely acknowledged as a tough issue when applying a MAC system in practice. The other is that, rather than restricting information flow as a traditional MAC does, it traces intruders and restricts only their critical malware behaviors, where intruders represent processes and executables that are potential agents of a remote attacker. Our prototyping and experiments on Windows show that Tracer can effectively defeat all malware samples tested via blocking malware behaviors while not causing a significant compatibility problem.
机译:在商业操作系统中实施实用的强制访问控制(MAC)以解决恶意软件问题既是一项艰巨的挑战,也是一种有前途的方法。应用MAC击败恶意软件程序的最大障碍是现有MAC系统中不兼容且无法使用的问题。为了解决这些问题,我们逐一和手动分析了2600种MAC强制执行的操作系统类型的2600个恶意软件样本,然后设计了一种名为Tracer的新颖MAC强制执行方法,该方法将入侵检测和跟踪功能整合到了商业操作系统中。从概念上讲,该方法包括三个操作:检测,跟踪和限制可疑入侵者。一种新颖之处在于,它利用轻量级入侵检测和跟踪技术来自动化安全标签配置,这在实践中应用MAC系统时被广泛认为是一个棘手的问题。另一个是,它没有像传统的MAC那样限制信息流,而是跟踪入侵者并仅限制其关键的恶意软件行为,其中入侵者代表了可能成为远程攻击者代理的进程和可执行文件。我们在Windows上进行的原型设计和实验表明,Tracer可以通过阻止恶意软件行为有效地击败所有测试的恶意软件样本,而不会引起严重的兼容性问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号