• DocumentCode
    3678510
  • Title

    Kernel Malware Core Implementation: A Survey

  • Author

    XiangYu Li;Yi Zhang;Yong Tang

  • Author_Institution
    Sch. of Comput. Sci., Nat. Univ. of Defense Technol., Changsha, China
  • fYear
    2015
  • Firstpage
    9
  • Lastpage
    15
  • Abstract
    Kernel Malware resides and performs malicious functions in the operating system kernel space. It is more difficult to be detected and cleared than the malwares implemented in the user space because of its higher authority. It also has better flexibility compared with the malware based on the firmware. As a result, the kernel malware is one of the challenging threats in information security. This paper analyzes the universal working model of the kernel malware and the attack vector, investigates the core implementation technologies. It focuses on the hook, patch and debug-based control flow hijacking and DKOM techniques. Then, the implementation details of these core technologies are analyzed by studying several typical Linux kernel malware. Finally, we summarize the detection methods of kernel malware, point out their main defects, and discuss the new direction of the malware detection.
  • Keywords
    "Kernel","Malware","File systems","Linux","Registers"
  • Publisher
    ieee
  • Conference_Titel
    Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC), 2015 International Conference on
  • Type

    conf

  • DOI
    10.1109/CyberC.2015.26
  • Filename
    7307780