Combating the OS-Level Malware in Mobile Devices by Leveraging Isolation and Steganography

Combating the OS-Level Malware in Mobile Devices by Leveraging Isolation and Steganography
复制标题

DOI:
10.1007/978-3-030-81645-2_23
复制
发表时间:
2021-06
期刊:
--
影响因子:
--
通讯作者:
Niusen Chen;Wenxue Xie;Bo Chen
Niusen Chen;Wenxue Xie;Bo Chen
中科院分区:
其他
文献类型:
--
作者:
Niusen Chen;Wenxue Xie;Bo Chen

文献摘要

被引文献

相似文献

检测操作系统级恶意软件(例如rootkit)是一个特别具有挑战性的问题,因为这种类型的恶意软件可以危害操作系统,然后可以很容易地隐藏其入侵行为或直接破坏传统的恶意软件检测器运行在用户或内核空间。在这项工作中,我们提出了mobiDOM来解决移动计算设备的这个问题。mobiDOM的核心思想是充分利用硬件中移动设备的现有安全特性,安全检测操作系统级恶意软件。具体来说,我们在flash转换层(FTL)中集成了一个恶意软件检测器,FTL是一个嵌入到操作系统无法访问的外部闪存中的固件层;此外,我们在Arm TrustZone安全环境中构建了一个受信任的应用程序,作为恶意软件检测器的用户级控制器。基于ftl的恶意软件检测器和基于trustzone的控制器通过隐写技术进行通信。安全性分析和实验评估验证了mobiDOM能够安全有效地检测os级恶意软件。
Detecting the OS-level malware (e.g., rootkit) is an especially challenging problem, as this type of malware can compromise the OS, and can then easily hide their intrusion behaviors or directly subvert the traditional malware detectors running in either the user or the kernel space. In this work, we propose mobiDOM to solve this problem for mobile computing devices. The key idea of mobiDOM is to securely detect the OS-level malware by fully utilizing the existing secure features of a mobile device in the hardware. Specifically, we integrate a malware detector in the flash translation layer (FTL), a firmware layer embedded into the external flash storage which is inaccessible to the OS; in addition, we build a trusted application in the Arm TrustZone secure world, which acts as a user-level controller of the malware detector. The FTL-based malware detector and the TrustZone-based controller communicate with each other stealthily via steganography. Security analysis and experimental evaluation confirm that mobiDOM can securely and effectively detect the OS-level malware.