A Hypervisor Level Provenance System to Reconstruct Attack Story Caused by Kernel Malware.

Lecture Notes of the Institute for Computer Sciences Social Informatics and Telecommunications Engineering(2017)

引用 5|浏览106
暂无评分
摘要
Provenance of system subjects (e.g., processes) and objects (e.g., files) are very useful for many forensics tasks. In our analysis and comparison of existing Linux provenance tracing systems, we found that most systems assume the Linux kernel to be in the trust base, making these systems vulnerable to kernel level malware. To address this problem, we present HProve, a hypervisor level provenance tracing system to reconstruct kernel malware attack story. It monitors the execution of kernel functions and sensitive objects, and correlates the system subjects and objects to form the causality dependencies for the attacks. We evaluated our prototype on 12 real world kernel malware samples, and the results show that it can correctly identify the provenance behaviors of the kernel malware.
更多
查看译文
关键词
Provenance tracing,Kernel malware,Forensic investigation
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要