loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Satyajit Grover ; Divya Naidu Kolar Sunder ; Samuel O. Moffatt and Michael E. Kounavis

Affiliation: Corporate Technology Group, Intel Corporation, United States

Keyword(s): Rootkits, Kernel, Security, Virtualization, Hypervisor.

Related Ontology Subjects/Areas/Topics: Information and Systems Security ; Security Engineering ; Security in Information Systems ; Security Information Systems Architecture and Design and Security Patterns

Abstract: In this paper we address the problem of protecting computer systems against stealth malware. The problem is important because the number of known types of stealth malware increases exponentially. Existing approaches have some advantages for ensuring system integrity but sophisticated techniques utilized by stealthy malware can thwart them. We propose Runtime Kernel Rootkit Detection (RKRD), a hardware-based, event-driven, secure and inclusionary approach to kernel integrity that addresses some of the limitations of the state of the art. Our solution is based on the principles of using virtualization hardware for isolation, verifying signatures coming from trusted code as opposed to malware for scalability and performing system checks driven by events. Our RKRD implementation is guided by our goals of strong isolation, no modifications to target guest OS kernels, easy deployment, minimal infrastructure impact, and minimal performance overhead. We developed a system prototype and condu cted a number of experiments which show that the performance impact of our solution is negligible. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 18.217.208.72

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Grover, S.; Naidu Kolar Sunder, D.; O. Moffatt, S. and E. Kounavis, M. (2008). AN EVENT-DRIVEN, INCLUSIONARY AND SECURE APPROACH TO KERNEL INTEGRITY. In Proceedings of the International Conference on Security and Cryptography (ICETE 2008) - SECRYPT; ISBN 978-989-8111-59-3; ISSN 2184-3236, SciTePress, pages 411-420. DOI: 10.5220/0001916004110420

@conference{secrypt08,
author={Satyajit Grover. and Divya {Naidu Kolar Sunder}. and Samuel {O. Moffatt}. and Michael {E. Kounavis}.},
title={AN EVENT-DRIVEN, INCLUSIONARY AND SECURE APPROACH TO KERNEL INTEGRITY},
booktitle={Proceedings of the International Conference on Security and Cryptography (ICETE 2008) - SECRYPT},
year={2008},
pages={411-420},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0001916004110420},
isbn={978-989-8111-59-3},
issn={2184-3236},
}

TY - CONF

JO - Proceedings of the International Conference on Security and Cryptography (ICETE 2008) - SECRYPT
TI - AN EVENT-DRIVEN, INCLUSIONARY AND SECURE APPROACH TO KERNEL INTEGRITY
SN - 978-989-8111-59-3
IS - 2184-3236
AU - Grover, S.
AU - Naidu Kolar Sunder, D.
AU - O. Moffatt, S.
AU - E. Kounavis, M.
PY - 2008
SP - 411
EP - 420
DO - 10.5220/0001916004110420
PB - SciTePress