A kernel stack protection model against attacks from kernel execution units. Issue 72 (January 2018)
- Record Type:
- Journal Article
- Title:
- A kernel stack protection model against attacks from kernel execution units. Issue 72 (January 2018)
- Main Title:
- A kernel stack protection model against attacks from kernel execution units
- Authors:
- Liu, Wangtong
Luo, Senlin
Liu, Yu
Pan, Limin
Safi, Qamas Gul Khan - Abstract:
- Abstract: Many defensive approaches have been proposed to protect the integrity of the operating system kernel stack. However, some types of attacks, such as the "return-to-schedule" rootkit, pose a serious threat to these approaches. In this paper, we present a kernel stack protection model to protect the integrity of the kernel stack. It adopts a synchronous design strategy to bind the execution unit with its kernel stack using virtualization technology, and allows the execution unit to write its own current kernel stack with legal kernel codes. To test the model, we propose three kinds of potential attacks which extend the "return-to-schedule" rootkit. The experimental results show that the prototype of the model can be effective against all attack methods, and introduces a performance cost of only 2%. Therefore, it effectively protects all types of data on the kernel stack with a small performance overhead.
- Is Part Of:
- Computers & security. Issue 72(2018)
- Journal:
- Computers & security
- Issue:
- Issue 72(2018)
- Issue Display:
- Volume 72, Issue 72 (2018)
- Year:
- 2018
- Volume:
- 72
- Issue:
- 72
- Issue Sort Value:
- 2018-0072-0072-0000
- Page Start:
- 96
- Page End:
- 106
- Publication Date:
- 2018-01
- Subjects:
- Virtualization -- Rootkit detection -- Control flow integrity -- Kernel stack integrity -- Ret-to-sched rootkit
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2017.09.008 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 8979.xml