• DocumentCode
    3057878
  • Title

    KVM-based Detection of Rootkit Attacks

  • Author

    Zhang, Xingjun ; Wang, Endong ; Xin, Long ; Wu, Zhongyuan ; Dong, Weiqing ; Dong, Xiaoshe

  • Author_Institution
    Dept. of Comput. Sci. & Technol., Xi´´an Jiaotong Univ., Xi´´an, China
  • fYear
    2011
  • fDate
    Nov. 30 2011-Dec. 2 2011
  • Firstpage
    703
  • Lastpage
    708
  • Abstract
    The kernel-level Root kit brings operating system mortal security risk. The existing detection methods, which are based on host environment, have limitations such as high Root kit privileges, weak isolation capacity. If the detected system, which may includes Root kit, and the detection system are resided on guest and host environment respectively, those limitations can be resolved. The paper proposed a method of Root kit detection based on KVM (Kernel-based Virtual Machine) by using virtualization technology. This method adopts guest memory protection mechanism, which is based on protection of host page tables and trusted code segments, for static kernel code and data. As for dynamically allocated code and data in heap space, this method introduces integrity checking mechanism, which is based on threshold triggering of calling sequences of monitored functions. The experimental results showed that this method can prevent static code or data from Root kit attacking effectively, and also detect attacks to dynamically allocated code or data quickly.
  • Keywords
    invasive software; operating system kernels; virtual machines; KVM-based detection; calling sequence threshold triggering; dynamically allocated code; heap space data; host page table protection; integrity checking mechanism; kernel-based virtual machine; kernel-level Rootkit attack; operating system security; static kernel code; static kernel data; trusted code segment protection; virtualization technology; weak isolation capacity; Data structures; Instruction sets; Kernel; Linux; Monitoring; Runtime; Semantics; KVM; Rootkit Detection; Virtualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Intelligent Networking and Collaborative Systems (INCoS), 2011 Third International Conference on
  • Conference_Location
    Fukuoka
  • Print_ISBN
    978-1-4577-1908-0
  • Type

    conf

  • DOI
    10.1109/INCoS.2011.111
  • Filename
    6132895