A lightweight kernel objects monitoring infrastructure for embedded systems

Lei Sun*, Tatsuo Nakajima

*この研究の対応する著者

研究成果: Conference contribution

6 被引用数 (Scopus)

抄録

In this paper, a lightweight system level monitoring infrastructure known as Kernel Objects Monitoring Infrastructure (KOMI) is presented for commercial-off-the-shelf (COTS) embedded systems. The kernel objects consist of certain critical kernel data structures and entry points of system calls, which are protected as first-class objects inside the system. KOMI provides specific runtime protections to different kernel objects: kernel data structures are protected by the periodic detection and recovery, the interception of arguments is used to protect vulnerable system calls. Both protection methods can provide not only consistency regulations but also recovery actions for the system. During its runtime deployment, once any system inconsistency has been detected, predefined recovery actions will be invoked. Since KOMI requires few modifications to kernel source code, it is easy to integrate into existing embedded systems. The evaluation experiment results indicate our prototype system can correctly detect the inconsistent kernel data structures caused by security attacks and also prevent kernel from exploits due to vulnerable system calls with acceptable penalty to the system performance. Moreover, KOMI is fully software-based without introducing any specific hardware and requires no modifications to system call APIs, therefore legacy applications can be also easily reused.

本文言語English
ホスト出版物のタイトルProceedings - 14th IEEE International Conference on Embedded and Real-Time Computing Systems and Applications, RTCSA 2008
ページ55-60
ページ数6
DOI
出版ステータスPublished - 2008 10月 15
イベント14th IEEE International Conference on Embedded and Real-Time Computing Systems and Applications, RTCSA 2008 - Kaohsiung, Taiwan, Province of China
継続期間: 2008 8月 252008 8月 27

出版物シリーズ

名前Proceedings - 14th IEEE International Conference on Embedded and Real-Time Computing Systems and Applications, RTCSA 2008

Conference

Conference14th IEEE International Conference on Embedded and Real-Time Computing Systems and Applications, RTCSA 2008
国/地域Taiwan, Province of China
CityKaohsiung
Period08/8/2508/8/27

ASJC Scopus subject areas

  • コンピュータ サイエンスの応用
  • ハードウェアとアーキテクチャ
  • 制御およびシステム工学
  • 電子工学および電気工学

フィンガープリント

「A lightweight kernel objects monitoring infrastructure for embedded systems」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル