中文版 | English
题名

Nighthawk: Transparent System Introspection from Ring -3

作者
通讯作者Zhang, Fengwei
DOI
发表日期
2019
会议名称
Proceedings of the 24th European Symposium on Research in Computer Security (ESORICS'19)
ISSN
16113349
会议录名称
卷号
11736 LNCS
页码
217-238
会议日期
September, 2019
会议地点
Luxembourg, Luxembourg
出版者
摘要

During the past decade, virtualization-based (e.g., virtual machine introspection) and hardware-assisted approaches (e.g., x86 SMM and ARM TrustZone) have been used to defend against low-level malware such as rootkits. However, these approaches either require a large Trusted Computing Base (TCB) or they must share CPU time with the operating system, disrupting normal execution. In this paper, we propose an introspection framework called Nighthawk that transparently checks system integrity at runtime. Nighthawk leverages the Intel Management Engine (IME), a co-processor that runs in isolation from the main CPU. By using the IME, our approach has a minimal TCB and incurs negligible overhead on the host system on a suite of indicative benchmarks. We use Nighthawk to check the integrity of the system software and firmware of a host system at runtime. The experimental results show that Nighthawk can detect real-world attacks against the OS, hypervisors, and System Management Mode while mitigating several classes of evasive attacks.
© 2019, Springer Nature Switzerland AG.

学校署名
通讯
收录类别
EI入藏号
20194807760461
EI主题词
Firmware ; Security Systems
EI分类号
Computer Software, Data HAndling And Applications:723 ; Accidents And Accident Prevention:914.1
来源库
EV Compendex
引用统计
被引频次[WOS]:8
成果类型会议论文
条目标识符http://sustech.caswiz.com/handle/2SGJ60CL/104902
专题工学院_计算机科学与工程系
作者单位
1.Central South University, Changsha, China
2.Wayne State University, Detroit, United States
3.Boise State University, Boise, United States
4.University of Michigan, Ann Arbor, United States
5.SUSTech, Shenzhen, China
6.Guangzhou University, Guangzhou, China
通讯作者单位南方科技大学
推荐引用方式
GB/T 7714
Zhou, Lei,Xiao, Jidong,Leach, Kevin,et al. Nighthawk: Transparent System Introspection from Ring -3[C]:Springer,2019:217-238.
条目包含的文件
文件名称/大小 文献类型 版本类型 开放类型 使用许可 操作
Nighthawk Transpare(461KB)----限制开放--
个性服务
原文链接
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
导出为Excel格式
导出为Csv格式
Altmetrics Score
谷歌学术
谷歌学术中相似的文章
[Zhou, Lei]的文章
[Xiao, Jidong]的文章
[Leach, Kevin]的文章
百度学术
百度学术中相似的文章
[Zhou, Lei]的文章
[Xiao, Jidong]的文章
[Leach, Kevin]的文章
必应学术
必应学术中相似的文章
[Zhou, Lei]的文章
[Xiao, Jidong]的文章
[Leach, Kevin]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
[发表评论/异议/意见]
暂无评论

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。