...
首页> 外文期刊>Security and Communications Networks >MOSKG: countering kernel rootkits with a secure paging mechanism
【24h】

MOSKG: countering kernel rootkits with a secure paging mechanism

机译:MOSKG:使用安全的分页机制对内核rootkit进行反制

获取原文
获取原文并翻译 | 示例
           

摘要

The kernel-level rootkits compromise the security of operating systems. In the current research studies, virtualization is used as a key tool against these attacks with virtualization-based memory protection. There are glitches in the memory protection mechanism, and it is vulnerable to page mapping attack and hard to be used for protecting dynamic data. To address these problems, we proposed a secure paging mechanism and constructed an external and transparent architecture named multiple operating systems kernel guard (MOSKG), which can protect critical kernel data in different operating systems like Windows and Linux, both of 32-bit and 64-bit. To evaluate our proposed architecture, we applied some experiments that are based on the study of kernel rootkits. The results show that MOSKG can protect critical kernel data from dynamic kernel object manipulation and page mapping attack, and it defeats all of the kernel-level attacks. It is also a significant conclusion that MOSKG only introduces a small performance overhead of 2.3%. Copyright (C) 2015 John Wiley & Sons, Ltd.
机译:内核级rootkit损害了操作系统的安全性。在当前的研究中,虚拟化被用作通过基于虚拟化的内存保护来抵御这些攻击的关键工具。内存保护机制存在故障,它很容易受到页面映射攻击的影响,很难用于保护动态数据。为了解决这些问题,我们提出了一种安全的分页机制,并构建了一个外部透明的体系结构,称为多操作系统内核防护(MOSKG),它可以保护Windows和Linux等32位和64位操作系统中的关键内核数据。位。为了评估我们提出的体系结构,我们应用了一些基于对内核rootkit的研究的实验。结果表明,MOSKG可以保护关键内核数据免受动态内核对象操纵和页面映射攻击的侵害,并且可以击败所有内核级攻击。 MOSKG仅引入了2.3%的较小性能开销,这也是一个重要的结论。版权所有(C)2015 John Wiley&Sons,Ltd.

著录项

  • 来源
    《Security and Communications Networks》 |2015年第18期|3580-3591|共12页
  • 作者单位

    Beijing Inst Technol, Informat Syst & Secur & Countermeasures Expt Ctr, Beijing 100081, Peoples R China;

    Beijing Inst Technol, Informat Syst & Secur & Countermeasures Expt Ctr, Beijing 100081, Peoples R China;

    Beijing Inst Technol, Informat Syst & Secur & Countermeasures Expt Ctr, Beijing 100081, Peoples R China;

    Beijing Inst Technol, Informat Syst & Secur & Countermeasures Expt Ctr, Beijing 100081, Peoples R China;

    Beijing Inst Technol, Informat Syst & Secur & Countermeasures Expt Ctr, Beijing 100081, Peoples R China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    virtualization; memory protection; kernel integrity; rootkit; kernel-level attacks;

    机译:虚拟化;内存保护;内核完整性;rootkit;内核级攻击;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号