跳到主要导航 跳到搜索 跳到主要内容

MOSKG: Countering kernel rootkits with a secure paging mechanism

  • Guanglu Yan
  • , Senlin Luo
  • , Fan Feng
  • , Limin Pan*
  • , Qamas Gul Khan Safi
  • *此作品的通讯作者
  • Beijing Institute of Technology

科研成果: 期刊稿件文章同行评审

摘要

The kernel-level rootkits compromise the security of operating systems. In the current research studies, virtualization is used as a key tool against these attacks with virtualization-based memory protection. There are glitches in the memory protection mechanism, and it is vulnerable to page mapping attack and hard to be used for protecting dynamic data. To address these problems, we proposed a secure paging mechanism and constructed an external and transparent architecture named multiple operating systems kernel guard (MOSKG), which can protect critical kernel data in different operating systems like Windows and Linux, both of 32-bit and 64-bit. To evaluate our proposed architecture, we applied some experiments that are based on the study of kernel rootkits. The results show that MOSKG can protect critical kernel data from dynamic kernel object manipulation and page mapping attack, and it defeats all of the kernel-level attacks. It is also a significant conclusion that MOSKG only introduces a small performance overhead of 2.3%.

源语言英语
页(从-至)3580-3591
页数12
期刊Security and Communication Networks
8
18
DOI
出版状态已出版 - 1 12月 2015

学术指纹

探究 'MOSKG: Countering kernel rootkits with a secure paging mechanism' 的科研主题。它们共同构成独一无二的学术指纹。

引用此