基于虚拟机监控器的 Windows 内核动态分配内存完整性与机密性主动数据保护
密码学与安全
2018-05-31 v1
摘要
操作系统安全的主要问题之一是在不可信环境中提供可信代码执行。在执行期间,内核模式驱动动态分配内存以存储和处理其数据:Windows 核心内核结构、用户私有信息以及第三方驱动的敏感数据。所有这些数据都可能被内核模式恶意软件篡改。针对基于 Windows 的计算机的攻击不仅可导致隐藏恶意驱动、进程权限提升和窃取私有数据,还可造成工业数控机床故障。Windows 内置安全机制和现有方法无法提供第三方驱动分配内存的完整性和机密性。所提出的基于虚拟机监控器的系统(AllMemPro)保护分配数据免遭修改或窃取。AllMemPro 阻止对哪怕 1 字节分配数据的访问,实时适应新分配内存,且无需驱动源代码即可保护驱动。AllMemPro 在最新的 Windows 10 1709 x64 上运行良好。
引用
@article{arxiv.1805.11847,
title = {Hypervisor-Based Active Data Protection for Integrity and Confidentiality of Dynamically Allocated Memory in Windows Kernel},
author = {Igor Korkin},
journal= {arXiv preprint arXiv:1805.11847},
year = {2018}
}
备注
Proceedings of the 13th annual Conference on Digital Forensics, Security and Law (CDFSL), University of Texas at San Antonio (UTSA), San Antonio, Texas. May 17-18 2018. 24 pages, 8 figures, 8 tables, 72 references