2019
DOI: 10.1109/msec.2019.2910218
|View full text |Cite
|
Sign up to set email alerts
|

Hypervisor-Based White Listing of Executables

Abstract: This paper describes an efficient system for ensuring code integrity of an OS, including its own-code and applications. We claim that the proposed system can protect from an attacker that has full control over the OS kernel. An evaluation of the system's performance suggests that the induced overhead is negligible.

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
1
0

Year Published

2020
2020
2024
2024

Publication Types

Select...
5
2
1

Relationship

2
6

Authors

Journals

citations
Cited by 9 publications
(3 citation statements)
references
References 4 publications
0
1
0
Order By: Relevance
“…However, the threat model often assumes that the kernel code is not to be trusted. Our method can be extended with a kernel integrity verification method (Leon et al 2018). Because the performance impact of the method described in (Leon et al 2018) is negligible, we believe the combination with our method will not yield a significant performance loss.…”
Section: Kernel Integritymentioning
confidence: 99%
“…However, the threat model often assumes that the kernel code is not to be trusted. Our method can be extended with a kernel integrity verification method (Leon et al 2018). Because the performance impact of the method described in (Leon et al 2018) is negligible, we believe the combination with our method will not yield a significant performance loss.…”
Section: Kernel Integritymentioning
confidence: 99%
“…In the specific domain of hypervisor technologies, [13] suggested a monitoring technique that can keep executables in check throughout runtime. Two modes of operations are proposed: user mode and kernel mode.…”
Section: B Runtime Security Monitoringmentioning
confidence: 99%
“…Leon et al [28] proposed a system that prevents the execution of unauthorized code in user mode. This system is also based on a thin hypervisor.…”
Section: Related Workmentioning
confidence: 99%