跳到主要导航 跳到搜索 跳到主要内容

A kernel stack protection model against attacks from kernel execution units

  • Wangtong Liu*
  • , Senlin Luo
  • , Yu Liu
  • , Limin Pan
  • , Qamas Gul Khan Safi
  • *此作品的通讯作者
  • Beijing Institute of Technology

科研成果: 期刊稿件文章同行评审

摘要

Many defensive approaches have been proposed to protect the integrity of the operating system kernel stack. However, some types of attacks, such as the “return-to-schedule” rootkit, pose a serious threat to these approaches. In this paper, we present a kernel stack protection model to protect the integrity of the kernel stack. It adopts a synchronous design strategy to bind the execution unit with its kernel stack using virtualization technology, and allows the execution unit to write its own current kernel stack with legal kernel codes. To test the model, we propose three kinds of potential attacks which extend the “return-to-schedule” rootkit. The experimental results show that the prototype of the model can be effective against all attack methods, and introduces a performance cost of only 2%. Therefore, it effectively protects all types of data on the kernel stack with a small performance overhead.

源语言英语
页(从-至)96-106
页数11
期刊Computers and Security
72
DOI
出版状态已出版 - 1月 2018

指纹

探究 'A kernel stack protection model against attacks from kernel execution units' 的科研主题。它们共同构成独一无二的指纹。

引用此