DocumentCode
2814349
Title
The Study of Response Model & Mechanism Against Windows Kernel Compromises
Author
Dong Hwi Lee ; Jae Myung Kim ; Choi, Kyong-Ho ; Kim, Kuinam J.
Author_Institution
Dept. of Inf. Security, Kyonggi Univ., Seoul
fYear
2008
fDate
28-30 Aug. 2008
Firstpage
600
Lastpage
608
Abstract
Malicious codes have been widely documented and detected in information security breach occurrences of Microsoft Windows platform. Legacy information security systems are particularly vulnerable to breaches, due to Window kernel-based malicious codes,that penetrate existing protection and remain undetected. To date there has not been enough quality study into and information sharing about Windows kernel and inner code mechanisms, and this is the corereason for the success of these codes into entering systems and remaining undetected. This paper focus on classification and formalization of type, target and mechanism of various Windows kernel-based attacks, and will present suggestions for effective response methodologies in the categories of ; "Kernel memory protection", "process & driver protection" and "File system & registry protection". An effective Windows kernel protection system will be presented through the collection and analysis of Windows kernel and inside mechanisms, and through suggestions for the implementation methodologies of unreleased and new Windows kernel protection skill. Results presented in this paper will explain that the suggested system be highly effective and has more accurate for intrusion detection ratios, then the current legacy security systems (i.e., virus vaccines, and Windows IPS, etc) intrusion detection ratios. So, It is expected that the suggested system provides a good solution to prevent IT infrastructure from complicated and intelligent Windows kernel attacks.
Keywords
invasive software; operating system kernels; Microsoft Window platform; Window kernel memory protection; file system-registry protection; information sharing; intrusion detection; legacy information security system; malicious code; process-driver protection; response model-mechanism; Application software; File systems; Information security; Information technology; Intrusion detection; Kernel; Microprocessors; Operating systems; Protection; Vaccines; Information Security; Kernel Attack; Malicious Codes;
fLanguage
English
Publisher
ieee
Conference_Titel
Convergence and Hybrid Information Technology, 2008. ICHIT '08. International Conference on
Conference_Location
Daejeon
Print_ISBN
978-0-7695-3328-5
Type
conf
DOI
10.1109/ICHIT.2008.235
Filename
4622892
Link To Document