DocumentCode :
3724462
Title :
Proposal of Kernel Rootkits Detection Method by Monitoring Branches Using Hardware Features
Author :
Yohei Akao;Toshihiro Yamauchi
Author_Institution :
Grad. Sch. of Natural Sci. &
fYear :
2015
fDate :
7/1/2015 12:00:00 AM
Firstpage :
721
Lastpage :
722
Abstract :
Attacks on computer systems have become more frequent in recent years. Attacks using kernel root kits pose a particularly serious threat. When a computer system is infected with a kernel root kit, attack detection is difficult. Because of this, handling the attack will be delayed causing an increase in the amount of damage done to the computer system. This paper proposes a new method to detect kernel root kits by monitoring the branch records in kernel space using hardware features of commodity processors. Our method utilizes the fact that many kernel root kits make branches that differ from the usual branches. By introducing our method, it is possible to detect kernel root kits immediately and, thereby, reduce damages to a minimum.
Keywords :
"Kernel","Monitoring","Computers","Control systems","Hardware","Feature extraction","Program processors"
Publisher :
ieee
Conference_Titel :
Advanced Applied Informatics (IIAI-AAI), 2015 IIAI 4th International Congress on
Print_ISBN :
978-1-4799-9957-6
Type :
conf
DOI :
10.1109/IIAI-AAI.2015.243
Filename :
7374006
Link To Document :
بازگشت