Title :
Behavior based authentication mechanism to prevent malicious code attacks in windows
Author :
Muthumanickam, K. ; Ilavarasan, E.
Author_Institution :
Dept. of CSE, Pondicherry Eng. Coll., Pondicherry, India
Abstract :
Most modern kernel of the operating system fails to ensure the authenticity of a suspicious process while servicing its system call. As a result, preventing kernel level malicious code attacks that target system table hooking becomes a challenging and serious security issue. The traditional process authentication techniques such as the process name, process identifier and execution path exercised by the kernel are not reliable. Therefore, in this paper, we proposed a kernel level authentication prototype to verify the originality of each suspicious process during runtime. The verification and authentication tasks are performed well in advance before each suspicious process getting the kernel service. We designed, implemented, and assessed the prototype in Windows. The evaluation results confirm that the prototype successfully blocked all malicious code attacks that target invoking system services directly in the kernel mode with minimal overhead.
Keywords :
operating systems (computers); security of data; Windows; behavior based authentication mechanism; malicious code attacks; operating system; process authentication techniques; Authentication; Kernel; Malware; Monitoring; Prototypes; Kernel; Operating System; Process Authentication; Windows;
Conference_Titel :
Innovations in Information, Embedded and Communication Systems (ICIIECS), 2015 International Conference on
Conference_Location :
Coimbatore
Print_ISBN :
978-1-4799-6817-6
DOI :
10.1109/ICIIECS.2015.7193071