首页> 外国专利> Snoop-based kernel integrity monitoring apparatus and method thereof

Snoop-based kernel integrity monitoring apparatus and method thereof

机译:基于监听的内核完整性监控装置及其方法

摘要

A snoop-based kernel integrity monitoring apparatus and a method thereof are provided. More particularly, provided are a kernel integrity monitoring apparatus which is provided as a hardware device independent of a host system, and snoops traffic occurring in a system bus of the host system and by detecting a write attempt in a kernel immutable region, monitors integrity of the kernel, and a method thereof. According to the apparatus and method, by analyzing traffic of the system bus of the host system, a write attempt in the kernel immutable region is detected. Thus, a transient attack which is difficult for a snapshot method to detect can be detected.
机译:提供了一种基于监听的内核完整性监视装置及其方法。更特别地,提供了一种内核完整性监视装置,其被提供为独立于主机系统的硬件设备,并且监听主机系统的系统总线中发生的业务,并且通过检测在内核不可变区域中的写入尝试,来监视内核完整性。内核及其方法。根据该装置和方法,通过分析主机系统的系统总线的业务量,检测到内核不可变区域中的写尝试。因此,可以检测快照方法难以检测的瞬时攻击。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号