A study of hardware-assisted event-triggered kernel integrity monitoring platform하드웨어 지원을 통한 이벤트 트리거 방식의 커널 무결성 검사 플랫폼

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 694
  • Download : 0
Kernel rootkit is a class of malware which manipulates the operating system kernel. Adversaries deploy kernel-level rootkits to perpetuate the intrusion by subverting the core functionalities in her favor. A kernel infected by a rootkit report false system status; traces of attacker such as files, processes, or network connections are hidden to the system status reporting tools. Furthermore, rootkits operate in kernel layer hold the highest privilege level, and are capable of evading or even incapacitating any in-system security measures. In turn, VMMs and hardwares have been proposed as roots of trust which provide a safe execution environment for monitoring softwares. VMMs are popularly used as a platform for kernel integrity monitoring because they innately monitor or intervene the operations of a guest system for virtualization. However, VMMs also have been exposed to the common software vulnerability attacks, implying that they can be compromised by rootkits as well. While external hardwares provide better isolation and security, the existing works either employed snapshot-based methods thus incurring a significant performance overhead, or limited to monitoring of kernel static region protection. Therefore, there is a need for a hardware-based integrity monitoring platforms that can monitor the dynamic regions of kernel with a negligible performance overhead.This thesis presents a hardware-based platform for event-triggered kernel integrity monitoring, called KI-Mon. The proposed platform provides a kernel integrity monitoring platform which is capable of monitoring mutable kernel objects. A refined form of bus traffic monitoring makes value verification of the objects efficient, and callback verification routines can be programmed and executed for a designated event space. The prototype of the proposed platform was implemented, and the experiments demonstrated the effectiveness of the prototype`s event-triggered mechanism and efficacy in terms of perform...
Advisors
Kang, Brent Byung-Hoonresearcher강병훈Choi, Key-Sun최기선
Description
한국과학기술원 : 정보보호대학원,
Publisher
한국과학기술원
Issue Date
2013
Identifier
567081/325007  / 020114463
Language
eng
Description

학위논문(석사) - 한국과학기술원 : 정보보호대학원, 2013.8, [ v, 36 p. ]

Keywords

Rootkit; Kernel Integrity; 악성코드; 루트킷; Malware; 커널 무결성

URI
http://hdl.handle.net/10203/197949
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=567081&flag=dissertation
Appears in Collection
IS-Theses_Master(석사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0