作者
Junghwan Rhee, Ryan Riley, Dongyan Xu, Xuxian Jiang
发表日期
2010/9/15
研讨会论文
International Workshop on Recent Advances in Intrusion Detection
页码范围
178-197
出版商
Springer, Berlin, Heidelberg
简介
Dynamic kernel memory has been a popular target of recent kernel malware due to the difficulty of determining the status of volatile dynamic kernel objects. Some existing approaches use kernel memory mapping to identify dynamic kernel objects and check kernel integrity. The snapshot-based memory maps generated by these approaches are based on the kernel memory which may have been manipulated by kernel malware. In addition, because the snapshot only reflects the memory status at a single time instance, its usage is limited in temporal kernel execution analysis. We introduce a new runtime kernel memory mapping scheme called allocation-driven mapping, which systematically identifies dynamic kernel objects, including their types and lifetimes. The scheme works by capturing kernel object allocation and deallocation events. Our system provides a number of unique benefits to kernel malware …
引用总数
201120122013201420152016201720182019202020212022202355769611572415
学术搜索中的文章
J Rhee, R Riley, D Xu, X Jiang - Recent Advances in Intrusion Detection: 13th …, 2010