Publication | Closed Access
Automated detection of persistent kernel control-flow attacks
297
Citations
30
References
2007
Year
Unknown Venue
EngineeringInformation SecuritySoftware AnalysisFormal VerificationSbcfi EnforcementSystems EngineeringUnexpected ModificationOs-level VirtualizationRuntime VerificationOperating System SecurityComputer EngineeringControl-flow GraphComputer ScienceSecurity Testing MethodData SecurityOperating SystemsProgram AnalysisAttack ModelSoftware TestingUnikernelsSystem SoftwareVirtual Machine
This paper presents a new approach to dynamically monitoring operating system kernel integrity, based on a property called state-based control-flow integrity (SBCFI). Violations of SBCFI signal a persistent, unexpected modification of the kernel's control-flow graph. We performed a thorough analysis of 25 Linux rootkits and found that 24 (96%) employ persistent control-flow modifications; an informal study of Windows rootkits yielded similar results. We have implemented SBCFI enforcement as part of the Xen and VMware virtual machine monitors. Our implementation detected all the control-flow modifying rootkits we could install, while imposing unnoticeable overhead for both a typical web server workload and CPU-intensive workloads when operating at 10 second intervals.
| Year | Citations | |
|---|---|---|
Page 1
Page 1