Position Paper: Consider Hardware-enhanced Defenses for Rootkit Attacks

Position Paper: Consider Hardware-enhanced Defenses for Rootkit Attacks
复制标题

DOI:
10.1145/3458903.3458909
复制
发表时间:
2020-10
期刊:
Hardware and Architectural Support for Security and Privacy
影响因子:
--
通讯作者:
Guangyuan Hu;Tianwei Zhang;Ruby B. Lee
Guangyuan Hu;Tianwei Zhang;Ruby B. Lee
中科院分区:
其他
文献类型:
--
作者:
Guangyuan Hu;Tianwei Zhang;Ruby B. Lee

文献摘要

相似文献

Rootkit是一种恶意软件,它试图破坏系统的功能,同时隐藏它们的存在。已经提出了各种rootkit以及不同的软件防御,但只有很少的硬件防御。我们定位硬件增强的rootkit防御作为一个有趣的研究机会,计算机架构师,特别是许多新的硬件防御投机执行攻击正在积极考虑。我们首先描述rootkit使用的不同技术及其在操作系统中的主要目标。然后,我们试图阐明在提供rootkit防御方面的主要挑战是什么,以及如何克服这些挑战。我们展示了如何实现基于虚拟机管理程序的防御,并提供了一个完整的原型实现在一个开源的云计算平台,OpenStack。我们评估了不同防御机制的性能开销。最后,我们指出了一些研究机会,以提高弹性rootkit类攻击的硬件架构。
Rootkits are malware that attempt to compromise the system’s functionalities while hiding their existence. Various rootkits have been proposed as well as different software defenses, but only very few hardware defenses. We position hardware-enhanced rootkit defenses as an interesting research opportunity for computer architects, especially as many new hardware defenses for speculative execution attacks are being actively considered. We first describe different techniques used by rootkits and their prime targets in the operating system. We then try to shed insights on what the main challenges are in providing a rootkit defense, and how these may be overcome. We show how a hypervisor-based defense can be implemented, and provide a full prototype implementation in an open-source cloud computing platform, OpenStack. We evaluate the performance overhead of different defense mechanisms. Finally, we point to some research opportunities for enhancing resilience to rootkit-like attacks in the hardware architecture.