返回
A Kernel Rootkit Detection Approach Based on Virtualization and Machine Learning
DOI:10.1109/ACCESS.2019.2928060.png)
摘要
En 中文
OS kernel is the core part of the operating system, and it plays an important role for OS resource management. A popular way to compromise OS kernel is through a kernel rootkit (i.e., malicious kernel module). Once a rootkit is loaded into the kernel space, it can carry out arbitrary malicious operations with high privilege. To defeat kernel rootkits, many approaches have been proposed in the past few years. However, existing methods suffer from some limitations: 1) most methods focus on user-mode rootkit detection; 2) some methods are limited to detect obfuscated kernel modules; and 3) some methods introduce significant performance overhead. To address these problems, we propose VKRD, a kernel rootkit detection system based on the hardware assisted virtualization technology. Compared with previous methods, VKRD can provide a transparent and an efficient execution environment for the target kernel module to reveal its run-time behavior. To select the important run-time features for training our detection models, we utilize the TF-IDF method. By combining the hardware assisted virtualization and machine learning techniques, our kernel rootkit detection solution could be potentially applied in the cloud environment. The experiments show that our system can detect windows kernel rootkits with high accuracy and moderate performance cost.
Keyword:
OS
kernel rootkit
virtualization
machine learning
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
3.6
论文数:
9.8W
被引数:
29.4W
机构
引用论文
Partial purification and characterization of a lipolytic enzyme from spores of the arbuscular mycorrhizal fungusGlomus versiforme
Mycologia
IF0
Structural Changes in Lumirhodopsin and Metarhodopsin I Studied by Their Photoreactions at 77 K
Biochemistry
IF0
In vitro evaluation of the cellular effect of indium tin oxide nanoparticles using the human lung adenocarcinoma A549 cells
Metallomics
IF0

