作者
Ryan Riley, Xuxian Jiang, Dongyan Xu
发表日期
2008
期刊
Recent Advances in Intrusion Detection
页码范围
1-20
出版商
Springer Berlin/Heidelberg
简介
Kernel rootkits pose a significant threat to computer systems as they run at the highest privilege level and have unrestricted access to the resources of their victims. Many current efforts in kernel rootkit defense focus on the detection of kernel rootkits – after a rootkit attack has taken place, while the smaller number of efforts in kernel rootkit prevention exhibit limitations in their capability or deployability. In this paper we present a kernel rootkit prevention system called NICKLE which addresses a common, fundamental characteristic of most kernel rootkits: the need for executing their own kernel code. NICKLE is a lightweight, virtual machine monitor (VMM) based system that transparently prevents unauthorized kernel code execution for unmodified commodity (guest) OSes. NICKLE is based on a new scheme called memory shadowing, wherein the trusted VMM maintains a shadow physical memory for a …
引用总数
2008200920102011201220132014201520162017201820192020202120222023202422645534143474741372913181112101