题名 | Nighthawk: Transparent System Introspection from Ring -3 |
作者 | |
通讯作者 | Zhang, Fengwei |
DOI | |
发表日期 | 2019
|
会议名称 | Proceedings of the 24th European Symposium on Research in Computer Security (ESORICS'19)
|
ISSN | 16113349
|
会议录名称 | |
卷号 | 11736 LNCS
|
页码 | 217-238
|
会议日期 | September, 2019
|
会议地点 | Luxembourg, Luxembourg
|
出版者 | |
摘要 | During the past decade, virtualization-based (e.g., virtual machine introspection) and hardware-assisted approaches (e.g., x86 SMM and ARM TrustZone) have been used to defend against low-level malware such as rootkits. However, these approaches either require a large Trusted Computing Base (TCB) or they must share CPU time with the operating system, disrupting normal execution. In this paper, we propose an introspection framework called Nighthawk that transparently checks system integrity at runtime. Nighthawk leverages the Intel Management Engine (IME), a co-processor that runs in isolation from the main CPU. By using the IME, our approach has a minimal TCB and incurs negligible overhead on the host system on a suite of indicative benchmarks. We use Nighthawk to check the integrity of the system software and firmware of a host system at runtime. The experimental results show that Nighthawk can detect real-world attacks against the OS, hypervisors, and System Management Mode while mitigating several classes of evasive attacks. |
学校署名 | 通讯
|
收录类别 | |
EI入藏号 | 20194807760461
|
EI主题词 | Firmware
; Security Systems
|
EI分类号 | Computer Software, Data HAndling And Applications:723
; Accidents And Accident Prevention:914.1
|
来源库 | EV Compendex
|
引用统计 |
被引频次[WOS]:8
|
成果类型 | 会议论文 |
条目标识符 | http://sustech.caswiz.com/handle/2SGJ60CL/104902 |
专题 | 工学院_计算机科学与工程系 |
作者单位 | 1.Central South University, Changsha, China 2.Wayne State University, Detroit, United States 3.Boise State University, Boise, United States 4.University of Michigan, Ann Arbor, United States 5.SUSTech, Shenzhen, China 6.Guangzhou University, Guangzhou, China |
通讯作者单位 | 南方科技大学 |
推荐引用方式 GB/T 7714 |
Zhou, Lei,Xiao, Jidong,Leach, Kevin,et al. Nighthawk: Transparent System Introspection from Ring -3[C]:Springer,2019:217-238.
|
条目包含的文件 | ||||||
文件名称/大小 | 文献类型 | 版本类型 | 开放类型 | 使用许可 | 操作 | |
Nighthawk Transpare(461KB) | -- | -- | 限制开放 | -- |
|
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。
修改评论