TY - GEN
T1 - A lightweight monitoring service for multi-core embedded systems
AU - Shimada, Hiromasa
AU - Courbot, Alexandre
AU - Kinebuchi, Yuki
AU - Nakajima, Tatsuo
PY - 2010/7/26
Y1 - 2010/7/26
N2 - The recent increase in complexity and functionality in embedded systems makes them more vulnerable to rootkit-type attacks, raising the need for integrity management systems. However, as of today there is no such system that can guarantee the system's safety while matching the low-resource, real-time and multi-core requirements of embedded systems. In this paper, we present a Virtual Machine Monitor (VMM) based monitoring service for embedded systems that checks the actual kernel data against a safe data specification. However, due to the VMM and multi-core nature of the system, the guest OS can be preempted at any time, leading to the checking of potentially inconsistent states. We evaluated two approaches to solve this problem: detecting such invalid states by checking specific kernel data, and detecting system calls using the VMM.
AB - The recent increase in complexity and functionality in embedded systems makes them more vulnerable to rootkit-type attacks, raising the need for integrity management systems. However, as of today there is no such system that can guarantee the system's safety while matching the low-resource, real-time and multi-core requirements of embedded systems. In this paper, we present a Virtual Machine Monitor (VMM) based monitoring service for embedded systems that checks the actual kernel data against a safe data specification. However, due to the VMM and multi-core nature of the system, the guest OS can be preempted at any time, leading to the checking of potentially inconsistent states. We evaluated two approaches to solve this problem: detecting such invalid states by checking specific kernel data, and detecting system calls using the VMM.
UR - http://www.scopus.com/inward/record.url?scp=77954787341&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=77954787341&partnerID=8YFLogxK
U2 - 10.1109/ISORC.2010.12
DO - 10.1109/ISORC.2010.12
M3 - Conference contribution
AN - SCOPUS:77954787341
SN - 9780769540375
T3 - ISORC 2010 - 2010 13th IEEE International Symposium on Object/Component/Service-Oriented Real-Time Distributed Computing
SP - 202
EP - 209
BT - ISORC 2010 - 2010 13th IEEE International Symposium on Object/Component/Service-Oriented Real-Time Distributed Computing
T2 - 13th IEEE International Symposium on Object, Component, and Service-Oriented Real-Time Distributed Computing, ISORC 2010
Y2 - 5 May 2010 through 6 May 2010
ER -