跳到主要导航 跳到搜索 跳到主要内容

Design and implementation of a model for OS kernel integrity protection

科研成果: 期刊稿件文章同行评审

摘要

Untrusted kernel extensions were considered to be a big threat to OS kernel integrity because once they were loaded into the kernel space, then they may corrupt both the OS kernel data and code at will. To address this problem, MAC-based model named MOKIP for OS kernel integrity protection was presented. The basic idea of MOKIP was to set different integrity labels for different entities in the kernel space, and then ensure that the entities with low integrity label cannot harm the entities with high integrity label. A prototype system based on the hardware assisted virtualization technology was implemented. The experimental results show that proposed system is effective at defending against various malicious kernel extension attacks within a little performance overhead which is less than 13%.

源语言英语
文章编号2015289
期刊Tongxin Xuebao/Journal on Communications
36
DOI
出版状态已出版 - 1 11月 2015

指纹

探究 'Design and implementation of a model for OS kernel integrity protection' 的科研主题。它们共同构成独一无二的指纹。

引用此