节点文献

OPKH:轻量级在线保护内核模块中内核钩子的方法(英文)

OPKH: A Lightweight Online Approach to Protecting Kernel Hooks in Kernel Modules

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 田东海李轩涯胡昌振闫怀志

【Author】 TIAN Donghai;LI Xuanya;HU Changzhen;YAN Huaizhi;Beijing Key Laboratory of Software Security Engineering Technique,School of Software, Beijing Institute of Technology;State Key Laboratory of Information Security,Institute of Information Engineering, Chinese Academy of Sciences;National Engineering Laboratory for Information Security Technologies,Institute of Information Engineering, Chinese Academy of Sciences;

【机构】 Beijing Key Laboratory of Software Security Engineering Technique,School of Software, Beijing Institute of TechnologyState Key Laboratory of Information Security,Institute of Information Engineering, Chinese Academy of SciencesNational Engineering Laboratory for Information Security Technologies,Institute of Information Engineering, Chinese Academy of Sciences

【摘要】 Kernel hooks are very important control data in OS kernel.Once these data are compromised by attackers,they can change the control flow of OS kernel’s execution.Previous solutions suffer from limitations in that:1)some methods require modifying the source code of OS kernel and kernel modules,which is less practical for wide deployment;2)other methods cannot well protect the kernel hooks and function return addresses inside kernel modules whose memory locations cannot be predetermined.To address these problems,we propose OPKH,an on-the-fly hook protection system based on the virtualization technology.Compared with previous solutions,OPKH offers the protected OS a fully transparent environment and an easy deployment.In general,the working procedure of OPKH can be divided into two steps.First,we utilise the memory virtualization for offline profiling so that the dynamic hooks can be identified.Second,we exploit the online patching technique to instrument the hooks for run-time protection.The experiments show that our system can protect the dynamic hooks effectively with minimal performance overhead.

【Abstract】 Kernel hooks are very important control data in OS kernel. Once these data are compromised by attackers, they can change the control flow of OS kernel’s execution. Previous solutions suffer from limitations in that: 1) some methods require modifying the source code of OS kernel and kernel modules, which is less practical for wide deployment; 2) other methods cannot well protect the kernel hooks and function return addresses inside kernel modules whose memory locations cannot be predetermined. To address these problems, we propose OPKH, an on-the-fly hook protection system based on the virtualization technology. Compared with previous solutions, OPKH offers the protected OS a fully transparent environment and an easy deployment. In general, the working procedure of OPKH can be divided into two steps. First, we utilise the memory virtualization for offline profiling so that the dynamic hooks can be identified. Second, we exploit the online patching technique to instrument the hooks for run-time protection. The experiments show that our system can protect the dynamic hooks effectively with minimal performance overhead.

【基金】 supported in part by the National High Technology Research and Development Program of China(863 Program)under Grant No.2009AA01Z433;the Project of National Ministry under Grant No.A21201-10006;the Open Foundation of State Key Laboratory of Information Security(Institute of Information Engineering,Chinese Academy of Sciences)under Grant No.2013-4-1
  • 【文献出处】 中国通信 ,China Communications , 编辑部邮箱 ,2013年11期
  • 【分类号】TP316
  • 【被引频次】1
  • 【下载频次】25
节点文献中: 

本文链接的文献网络图示:

本文的引文网络