DocumentCode :
3298374
Title :
Hardware-Assisted Application Integrity Monitor
Author :
Wang, Jiang ; Sun, Kun ; Stavrou, Angelos
Author_Institution :
Center for Secure Inf. Syst., George Mason Univ., Fairfax, VA, USA
fYear :
2012
fDate :
4-7 Jan. 2012
Firstpage :
5375
Lastpage :
5383
Abstract :
Existing hardware-assisted methods monitor the integrity of hyper visors and operating systems, which are critical to system integrity. This protection is possible because of ``non-volatile\´\´ data structures present in the machine\´s physical memory. In contrast, applications offer a more challenging protection target because they are dynamically allocated. Therefore, robust defenses against application tampering is still a difficult tasks that has remained an open problem. We propose "AppCheck," a hardware-assisted framework the protects the integrity of applications and server processes. We achieve that by leveraging semantic information extracted from the source code and input from a human developer. Unlike pure software defenses, AppCheck employs existing x86 features, namely System Management Mode, to acquire the necessary memory contents. If any of the these critical components become altered during runtime, AppCheck signals an alarm to a remote server notifying the operators of a potential security breach or software corruption.
Keywords :
data integrity; data structures; feature extraction; open systems; operating systems (computers); security of data; storage management; AppCheck signal; hardware-assisted application integrity monitor; human developer; hypervisor integrity; machine physical memory; nonvolatile data structure; open problem; operating system; security breach; semantic information extraction; server process; software corruption; software defense; source code; system integrity; system management mode; x86 feature; Hardware; Kernel; Linux; Monitoring; Servers; Integrity Monitor; System Management Mode;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
System Science (HICSS), 2012 45th Hawaii International Conference on
Conference_Location :
Maui, HI
ISSN :
1530-1605
Print_ISBN :
978-1-4577-1925-7
Electronic_ISBN :
1530-1605
Type :
conf
DOI :
10.1109/HICSS.2012.299
Filename :
6149545
Link To Document :
بازگشت