VMM-based Detection of Rootkits that Modify File Metadata
スポンサーリンク
概要
- 論文の詳細を見る
Kernel-level rootkits are posing an immense threat to any computer systems. They operate inside operating system kernels and manipulate crucial kernel data structures to bypass and evade anti-malware security tools. Combined with kernel-level rootkits, other malware such as bots, viruses and spyware becomes stealthy and difficult to detect. The focus of this paper is on typical kernel-level rootkits that falsify the contents of file systems to hide the presence of malware. In this paper, we propose a software based system that leverages virtual machine technology. Unlike traditional approaches, our system does not rely on signatures. Instead, it relies on the rootkit behavior that file system contents are falsified; it detects a mismatch between the file system view from user-level processes and that from the virtual machine monitor running under the operating system. The experimental results demonstrate that our system successfully detects real world kernel-level rootkits and the overhead of the system is reasonable.
- 一般社団法人情報処理学会の論文
- 2009-04-15
著者
-
Kenji Kono
Department of Information and Computer Science, Keio University
-
Kenji Kono
Department Of Information And Computer Science Keio University
-
Hiroshi Yamada
Keio University | CREST(JST)
-
Kenji Kono
Keio University | CREST(JST)
-
Makoto Shimamura
Keio University
関連論文
- A Strategy for Efficient Update Propagation on Peer-to-Peer Based Content Distribution Networks
- Using a Virtual Machine Monitor to Slow Down CPU Speed for Embedded Time-Sensitive Software Testing
- VMM-based Detection of Rootkits that Modify File Metadata
- VMM-based Detection of Rootkits that Modify File Metadata
- Strategy for Selecting Replica Server Spots on the Basis of Demand Fluctuations
- Introducing New Resource Management Policies Using a Virtual Machine Monitor
- An Analysis of Fake Antivirus Behaviors
- Automatically Checking for Session Management Vulnerabilities in Web Applications
- Using Fault Injection to Analyze the Scope of Error Propagation in Linux
- Screening Legitimate and Fake/Crude Antivirus Software