Publications

Detailed Information

DADE: a fast data anomaly detection engine for kernel integrity monitoring

Cited 1 time in Web of Science Cited 1 time in Scopus
Authors

Yi, Hayoon; Cho, Yeongpil; Paek, Yunheung; Ko, Kwangman

Issue Date
2019-08
Publisher
Kluwer Academic Publishers
Citation
Journal of Supercomputing, Vol.75 No.8, pp.4575-4600
Abstract
In computer systems, ensuring the integrity of the kernel assumes importance as attacks against the kernel allow an adversary to obtain the highest privilege within a compromised system. For this task, typically, an external monitor would perform memory introspection and verify the integrity of kernel data by checking whether certain integrity specifications hold or not. These specifications were commonly written by hand in the past. However, as adversaries turned their eyes to attacking a system through non-control kernel data, the need arose for verifying non-control kernel data, which is, unfortunately, nontrivial to do manually. Acknowledging this, Baliga et al. (Computer security applications conference, 2008. ACSAC 2008. Annual. IEEE, 2008) suggested a framework leveraging machine learning to generate integrity specifications. This generated specifications for both control and non-control data across the entire kernel with little human involvement. Unfortunately, there is a problem in the original design of this framework in regard to its practicality for deployment in real-world systems. In this paper, we propose a new design that accelerates the overall introspection process by virtually eliminating the booting delay that was needed in prior work. To evaluate the effectiveness of our design, we have implemented a prototype engine DADE and found that it only induces a delay of 68.49 ms with each reboot and a delay of 900 ms for an initial scan and an average of 160 ms for subsequent scans.
ISSN
0920-8542
URI
https://hdl.handle.net/10371/197621
DOI
https://doi.org/10.1007/s11227-017-2131-6
Files in This Item:
There are no files associated with this item.
Appears in Collections:

Altmetrics

Item View & Download Count

  • mendeley

Items in S-Space are protected by copyright, with all rights reserved, unless otherwise indicated.

Share