首页> 外文期刊>Software >Message filters for hardening the Linux kernel
【24h】

Message filters for hardening the Linux kernel

机译:消息过滤器,用于强化Linux内核

获取原文
获取原文并翻译 | 示例
       

摘要

Various mechanisms for hardening the Linux kernel (for example, enforcing system call policies, device driver failure recovery, protection against exploitation of bugs in code) are proposed in the literature. The main problem with these mechanisms is that, they require changes in the kernel code leading to the possibility of introducing new bugs and hence increasing the testing time. We propose a message filter model as an extension to object-oriented wrappers for the Linux kernel, to dynamically provide various filtering capabilities to the kernel. This model works as a comprehensive framework for specifying system call policies, handling device driver faults, protecting the kernel against exploits of bugs in code etc, without modifying the existing kernel code. This considerably reduces the possibility of creating new bugs in the kernel code. We have integrated policies for system call interception and device driver failure handling, into the Linux kernel (2.6.9), using message filter model. Our experiments show that the overhead due to our filter objects is very low, making it a useful mechanism for providing filtering capabilities to the Linux kernel. Copyright ? 2010 John Wiley & Sons, Ltd.
机译:文献中提出了各种加固Linux内核的机制(例如,实施系统调用策略,设备驱动程序故障恢复,防止利用代码错误的保护)。这些机制的主要问题在于,它们需要更改内核代码,从而可能引入新的错误,从而增加测试时间。我们提出了一个消息过滤器模型,作为Linux内核的面向对象包装器的扩展,以便为内核动态提供各种过滤功能。该模型可作为一个全面的框架,用于指定系统调用策略,处理设备驱动程序故障,保护内核免遭代码错误的利用等,而无需修改现有内核代码。这大大减少了在内核代码中创建新错误的可能性。我们使用消息过滤器模型将用于系统调用拦截和设备驱动程序故障处理的策略集成到Linux内核(2.6.9)中。我们的实验表明,由于我们的过滤器对象而导致的开销非常低,这使其成为为Linux内核提供过滤功能的有用机制。版权? 2010 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号