System Call Monitoring Using Authenticated System Calls

System Call Monitoring Using Authenticated System Calls
复制标题

DOI:
10.1109/tdsc.2006.41
复制
发表时间:
2006-07
影响因子:
7.3
通讯作者:
M. Rajagopalan;M. Hiltunen;T. Jim;R. Schlichting
M. Rajagopalan;M. Hiltunen;T. Jim;R. Schlichting
中科院分区:
计算机科学2区
文献类型:
--
作者:
M. Rajagopalan;M. Hiltunen;T. Jim;R. Schlichting

文献摘要

被引文献

相似文献

系统调用监控是一种通过在运行时检查每个系统调用是否符合指定程序正常行为的策略来检测和控制受损应用程序的技术。在这里,我们介绍一种基于经过身份验证的系统调用来实现系统调用监控的新方法。经过身份验证的系统调用是使用指定该调用策略的额外参数以及保证策略和系统调用参数完整性的加密消息身份验证代码进行扩充的系统调用。内核使用此额外信息来验证系统调用。常规系统调用已被经过身份验证的调用替换的应用程序版本是由安装程序自动生成的,该安装程序读取应用程序二进制文件,使用静态分析来生成策略,然后使用经过身份验证的调用重写二进制文件。本文介绍了该方法,描述了基于 Linux 和 PLTO 二进制重写系统的原型实现,并给出了实验结果,表明该方法能够以适度的成本有效地防止应用程序受到损害
System call monitoring is a technique for detecting and controlling compromised applications by checking at runtime that each system call conforms to a policy that specifies the program's normal behavior. Here, we introduce a new approach to implementing system call monitoring based on authenticated system calls. An authenticated system call is a system call augmented with extra arguments that specify the policy for that call, and a cryptographic message authentication code that guarantees the integrity of the policy and the system call arguments. This extra information is used by the kernel to verify the system call. The version of the application in which regular system calls have been replaced by authenticated calls is generated automatically by an installer program that reads the application binary, uses static analysis to generate policies, and then rewrites the binary with the authenticated calls. This paper presents the approach, describes a prototype implementation based on Linux and the PLTO binary rewriting system, and gives experimental results suggesting that the approach is effective in protecting against compromised applications at modest cost