TY - JOUR
T1 - A kernel stack protection model against attacks from kernel execution units
AU - Liu, Wangtong
AU - Luo, Senlin
AU - Liu, Yu
AU - Pan, Limin
AU - Safi, Qamas Gul Khan
N1 - Publisher Copyright:
© 2017 Elsevier Ltd
PY - 2018/1
Y1 - 2018/1
N2 - Many defensive approaches have been proposed to protect the integrity of the operating system kernel stack. However, some types of attacks, such as the “return-to-schedule” rootkit, pose a serious threat to these approaches. In this paper, we present a kernel stack protection model to protect the integrity of the kernel stack. It adopts a synchronous design strategy to bind the execution unit with its kernel stack using virtualization technology, and allows the execution unit to write its own current kernel stack with legal kernel codes. To test the model, we propose three kinds of potential attacks which extend the “return-to-schedule” rootkit. The experimental results show that the prototype of the model can be effective against all attack methods, and introduces a performance cost of only 2%. Therefore, it effectively protects all types of data on the kernel stack with a small performance overhead.
AB - Many defensive approaches have been proposed to protect the integrity of the operating system kernel stack. However, some types of attacks, such as the “return-to-schedule” rootkit, pose a serious threat to these approaches. In this paper, we present a kernel stack protection model to protect the integrity of the kernel stack. It adopts a synchronous design strategy to bind the execution unit with its kernel stack using virtualization technology, and allows the execution unit to write its own current kernel stack with legal kernel codes. To test the model, we propose three kinds of potential attacks which extend the “return-to-schedule” rootkit. The experimental results show that the prototype of the model can be effective against all attack methods, and introduces a performance cost of only 2%. Therefore, it effectively protects all types of data on the kernel stack with a small performance overhead.
KW - Control flow integrity
KW - Kernel stack integrity
KW - Ret-to-sched rootkit
KW - Rootkit detection
KW - Virtualization
UR - https://www.scopus.com/pages/publications/85029939093
U2 - 10.1016/j.cose.2017.09.008
DO - 10.1016/j.cose.2017.09.008
M3 - Article
AN - SCOPUS:85029939093
SN - 0167-4048
VL - 72
SP - 96
EP - 106
JO - Computers and Security
JF - Computers and Security
ER -