A Coprocessor-Based Introspection Framework Via Intel Management Engine

A Coprocessor-Based Introspection Framework Via Intel Management Engine
复制标题

DOI:
10.1109/tdsc.2021.3071092
复制
发表时间:
2021-07
影响因子:
7.3
通讯作者:
Lei Zhou;Fengwei Zhang;Jidong Xiao;Kevin Leach;Westley Weimer;Xuhua Ding;Guojun Wang
Lei Zhou;Fengwei Zhang;Jidong Xiao;Kevin Leach;Westley Weimer;Xuhua Ding;Guojun Wang
中科院分区:
计算机科学2区
文献类型:
--
作者:
Lei Zhou;Fengwei Zhang;Jidong Xiao;Kevin Leach;Westley Weimer;Xuhua Ding;Guojun Wang

文献摘要

相似文献

在过去的十年中,基于虚拟化的(例如,虚拟机自检)和硬件辅助方法(例如,x86 SMM和ARM TrustZone)已被用于防御低级别恶意软件,如rootkit。然而,这些方法要么需要大型可信计算基础(TCB),要么必须与操作系统共享CPU时间,从而中断正常执行。在这篇文章中,我们提出了一个名为Nighthawk的内省框架,透明地检查系统的完整性和监视目标系统的运行时状态。Nighthawk利用英特尔管理引擎(IME),这是一种与主CPU隔离运行的协处理器。通过使用IME,我们的方法具有最小的TCB,并且在一套指示性基准测试中对主机系统的开销可以忽略不计。我们使用Nighthawk来在运行时检查主机系统的系统软件和固件。实验结果表明,Nighthawk可以检测到针对操作系统,虚拟机管理程序和系统管理模式的真实攻击,同时减轻了几类规避攻击。此外,Nighthawk可以监视主机系统的运行时状态,以防止目标机器上运行的可疑应用程序。
During the past decade, virtualization-based (e.g., virtual machine introspection) and hardware-assisted approaches (e.g., x86 SMM and ARM TrustZone) have been used to defend against low-level malware such as rootkits. However, these approaches either require a large Trusted Computing Base (TCB) or they must share CPU time with the operating system, disrupting normal execution. In this article, we propose an introspection framework called Nighthawk that transparently checks system integrity and monitor the runtime state of target system. Nighthawk leverages the Intel Management Engine (IME), a co-processor that runs in isolation from the main CPU. By using the IME, our approach has a minimal TCB and incurs negligible overhead on the host system on a suite of indicative benchmarks. We use Nighthawk to introspect the system software and firmware of a host system at runtime. The experimental results show that Nighthawk can detect real-world attacks against the OS, hypervisors, and System Management Mode while mitigating several classes of evasive attacks. Additionally, Nighthawk can monitor the runtime state of host system against the suspicious applications running in target machine.