Title :
KVM-based Detection of Rootkit Attacks
Author :
Zhang, Xingjun ; Wang, Endong ; Xin, Long ; Wu, Zhongyuan ; Dong, Weiqing ; Dong, Xiaoshe
Author_Institution :
Dept. of Comput. Sci. & Technol., Xi´´an Jiaotong Univ., Xi´´an, China
fDate :
Nov. 30 2011-Dec. 2 2011
Abstract :
The kernel-level Root kit brings operating system mortal security risk. The existing detection methods, which are based on host environment, have limitations such as high Root kit privileges, weak isolation capacity. If the detected system, which may includes Root kit, and the detection system are resided on guest and host environment respectively, those limitations can be resolved. The paper proposed a method of Root kit detection based on KVM (Kernel-based Virtual Machine) by using virtualization technology. This method adopts guest memory protection mechanism, which is based on protection of host page tables and trusted code segments, for static kernel code and data. As for dynamically allocated code and data in heap space, this method introduces integrity checking mechanism, which is based on threshold triggering of calling sequences of monitored functions. The experimental results showed that this method can prevent static code or data from Root kit attacking effectively, and also detect attacks to dynamically allocated code or data quickly.
Keywords :
invasive software; operating system kernels; virtual machines; KVM-based detection; calling sequence threshold triggering; dynamically allocated code; heap space data; host page table protection; integrity checking mechanism; kernel-based virtual machine; kernel-level Rootkit attack; operating system security; static kernel code; static kernel data; trusted code segment protection; virtualization technology; weak isolation capacity; Data structures; Instruction sets; Kernel; Linux; Monitoring; Runtime; Semantics; KVM; Rootkit Detection; Virtualization;
Conference_Titel :
Intelligent Networking and Collaborative Systems (INCoS), 2011 Third International Conference on
Conference_Location :
Fukuoka
Print_ISBN :
978-1-4577-1908-0
DOI :
10.1109/INCoS.2011.111