1
Return

A closed-source driver protection method based on multidimensional domain switch

delete2026-06-16
delete0
PRE
AI
Y
YongGang Li *
A
Ao Che
Y
Yi Guo
Y
Yu Bao
DOI:10.1016/j.cose.2026.105015delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
In Linux systems, driver code is substantially more extensive than kernel code, resulting in a considerably larger attack surface. Notably, closed-source drivers furnished by third parties have not undergone source code-centric security audits, thereby posing heightened security risks. Kernel rootkits and Code Reuse Attacks (CRAs) constitute the primary threat vectors targeting closed-source drivers. In practice, closed-source drivers can be not only victims but also perpetrator. They may either actively facilitate attacks by exploiting their inherent vulnerabilities, or passively serve as carriers for various malicious payloads. Traditional Control Flow Integrity (CFI) methods face significant deployment challenges, as they are unable to construct high-precision Control Flow Graphs (CFGs) for closed-source drivers in the absence of source code. Meanwhile, existing Address Space Layout Randomization (ASLR) techniques struggle to effectively preserve the original code logic of closed-source drivers after randomization. To address these critical limitations, this paper proposes Deco, a novel defense method predicated on the principle of virtualization. Deco tracks and analyzes the runtime behavior of closed-source drivers, thereby eliminating reliance on source code. During driver execution, Deco dynamically switches the driver’s domains by manipulating its memory spaces and permissions, further enabling the capture of control flows involving cross-domain transfers. Subsequently, all cross-domain control flows are monitored and validated to preclude malicious exploitation. Experimental results demonstrate that Deco provides robust protection for closed-source drivers, incurring only a 2.7% overhead under general scenarios.

Journal

C
COMPUTERS & SECURITY
IF:
5.4
Papers:
164
Citations:
0

Organization

No organization information available
Cited Papers

Cited Papers

Citing Papers

Citing Papers