Automatically Generating External OS Kernel Integrity Checkers for Detecting Hidden Rootkits

Hiromasa Shimada, Tatsuo Nakajima

    研究成果: Conference contribution

    2 被引用数 (Scopus)

    抄録

    The integrity checker validates the data structures in a target OS kernel from outside to enhance system security. Because of a huge number of kernel data structures, all possible invariants cannot be generated automatically, as we encounter a combinatorial explosion. In this paper, we propose a framework to generate a practical integrity checker automatically without examining all data structures in an OS kernel. Hidden rootkits infect the pointer variables of kernel data structures, a filter proposed in the framework reduces the number of target kernel data structures without decreasing the detection accuracy. In our experiments, the proposed system generates an integrity checker for three Linux kernels in a practical time, and a generated integrity checker can detect all of the hidden root kits infecting the kernel data structures.

    本文言語English
    ホスト出版物のタイトルProceedings - 2014 IEEE International Conference on Ubiquitous Intelligence and Computing, 2014 IEEE International Conference on Autonomic and Trusted Computing, 2014 IEEE International Conference on Scalable Computing and Communications and Associated Symposia/Workshops, UIC-ATC-ScalCom 2014
    出版社Institute of Electrical and Electronics Engineers Inc.
    ページ441-448
    ページ数8
    ISBN(印刷版)9781479976461
    DOI
    出版ステータスPublished - 2015 10月 23
    イベント11th IEEE International Conference on Ubiquitous Intelligence and Computing and 11th IEEE International Conference on Autonomic and Trusted Computing and 14th IEEE International Conference on Scalable Computing and Communications and Associated Symposia/Workshops, UIC-ATC-ScalCom 2014 - Denpasar, Bali, Indonesia
    継続期間: 2014 12月 92014 12月 12

    Other

    Other11th IEEE International Conference on Ubiquitous Intelligence and Computing and 11th IEEE International Conference on Autonomic and Trusted Computing and 14th IEEE International Conference on Scalable Computing and Communications and Associated Symposia/Workshops, UIC-ATC-ScalCom 2014
    国/地域Indonesia
    CityDenpasar, Bali
    Period14/12/914/12/12

    ASJC Scopus subject areas

    • 人工知能
    • コンピュータ サイエンスの応用

    フィンガープリント

    「Automatically Generating External OS Kernel Integrity Checkers for Detecting Hidden Rootkits」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

    引用スタイル