中文版 | English
题名

KShot: Live Kernel Patching with SMM and SGX

作者
通讯作者Zhang,Fengwei
DOI
发表日期
2020-06-01
会议名称
Proceedings of the 50th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN'20)
ISSN
1530-0889
ISBN
978-1-7281-5810-5
会议录名称
页码
1-13
会议日期
June, 2020
会议地点
Valencia, Spain
摘要

Live kernel patching is an increasingly common trend in operating system distributions, enabling dynamic updates to include new features or to fix vulnerabilities without having to reboot the system. Patching the kernel at runtime lowers downtime and reduces the loss of useful state from running applications. However, existing kernel live patching techniques (1) rely on specific support from the target operating system, and (2) admit patch failures resulting from kernel faults. We present KSHOT, a kernel live patching mechanism based on x86 SMM and Intel SGX that focuses on patching Linux kernel security vulnerabilities. Our patching processes are protected by hardware-assisted Trusted Execution Environments. We demonstrate that our technique can successfully patch vulnerable kernel functions at the binary-level without support from the underlying OS and regardless of whether the kernel patching mechanism is compromised. We demonstrate the applicability of KSHOT by successfully patching 30 critical indicative kernel vulnerabilities.

关键词
学校署名
第一 ; 通讯
语种
英语
相关链接[Scopus记录]
收录类别
EI入藏号
20203709168159
EI分类号
Data Processing and Image Processing:723.2
Scopus记录号
2-s2.0-85090420125
来源库
Scopus
全文链接https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=9153415
引用统计
被引频次[WOS]:13
成果类型会议论文
条目标识符http://sustech.caswiz.com/handle/2SGJ60CL/187989
专题工学院_计算机科学与工程系
作者单位
1.Department of Computer Science and Engineering,Southern University of Science and Technology,Shenzhen,China
2.School of Computer Science and Engineering,Central South University,Changsha,China
3.Department of Computer Science,Wayne State University,Detroit,United States
4.Department of Computer Science,Boise State University,Boise,United States
5.Department of Computer Science and Engineering,University of Michigan,Ann Arbor,United States
6.School of Computer Science and Cyber Engineering,Guangzhou University,Guangzhou,China
第一作者单位计算机科学与工程系
通讯作者单位计算机科学与工程系
第一作者的第一单位计算机科学与工程系
推荐引用方式
GB/T 7714
Zhou,Lei,Zhang,Fengwei,Liao,Jinghui,et al. KShot: Live Kernel Patching with SMM and SGX[C],2020:1-13.
条目包含的文件
文件名称/大小 文献类型 版本类型 开放类型 使用许可 操作
KShot Live Kernel Pa(338KB)----限制开放--
个性服务
原文链接
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
导出为Excel格式
导出为Csv格式
Altmetrics Score
谷歌学术
谷歌学术中相似的文章
[Zhou,Lei]的文章
[Zhang,Fengwei]的文章
[Liao,Jinghui]的文章
百度学术
百度学术中相似的文章
[Zhou,Lei]的文章
[Zhang,Fengwei]的文章
[Liao,Jinghui]的文章
必应学术
必应学术中相似的文章
[Zhou,Lei]的文章
[Zhang,Fengwei]的文章
[Liao,Jinghui]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
[发表评论/异议/意见]
暂无评论

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。