DocumentCode :
2991031
Title :
Resisting Vicious Privilege Upgrade with Integrity Checking
Author :
Liu, Changping ; Fan, Mingyu ; Zheng, Xiuling ; Wang, Guangwei
Author_Institution :
Sch. of Comput. Sci. & Eng., Univ. of Electron. Sci. & Technol. of China, Chengdu, China
fYear :
2009
fDate :
18-20 Jan. 2009
Firstpage :
1
Lastpage :
4
Abstract :
Hole or bug of operating system (OS) is one source of vulnerabilities. Attacker usually upgrades itself to root privilege in vicious way using declared or covert holes on the compromised system. In this paper, we proposed a method to detect and resist vicious privilege upgrade based on integrity checking of trusted computing. At first, we calculated the secure hash values of the special executable code which upgrade privilege in legal way at relative safe status, and stored them in trusted platform model (TPM). Secondly, we embedded the anti-attack module in the scheduler of OS and kept pace with the scheduler. Once having detected privilege upgrade, we checked the integrity of current executable code with the pre-calculated secure hash values stored in TPM. Comparison mismatch explicated that object system was under attack. Object system terminated the current executable code immediately to resist vicious privilege upgrade. We realized this method based on Linux system and suggested an enhanced Linux kernel (ELK). Experiment result showed that this method can tolerate the existence of holes to a certain degree and safeguard system security from vicious privilege upgrade with acceptable cost.
Keywords :
Linux; security of data; OS scheduler; antiattack module; enhanced Linux kernel; integrity checking; object system; operating system; system security; trusted computing; trusted platform model; vicious privilege upgrade detection method; Computer bugs; Computer science; Kernel; Law; Legal factors; Linux; Operating systems; Processor scheduling; Resists; Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Network and Multimedia Technology, 2009. CNMT 2009. International Symposium on
Conference_Location :
Wuhan
Print_ISBN :
978-1-4244-5272-9
Type :
conf
DOI :
10.1109/CNMT.2009.5374771
Filename :
5374771
Link To Document :
بازگشت