Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.1145/2179298.2179377acmotherconferencesArticle/Chapter ViewAbstractPublication PagescsiirwConference Proceedingsconference-collections
research-article

Flying under the radar: maintaining control of kernel without changing kernel code or persistent data structures

Published: 12 October 2011 Publication History
First page of PDF

Supplementary Material

Supplemental material. (a69-wei_slide.pdf)

References

[1]
Abadi, M., Budiu, M., Erlingsson, U., and Ligatti, J. 2005. Control-flow integrity. In Proceedings of the 12th ACM Conference on Computer and Communications Security.
[2]
Boldewin, F. 2007. Peacomm.C - Cracking the nutshell. Anti Rootkit. http://www.antirootkit.com/articles/eye-of-the-storm-worm/Peacomm-C-Cracking-the-nutshell.html.
[3]
Bovet, D. and Cesati, M. 2002. Understanding the Linux Kernel, Second Edition. O'Reilly. ISBN: 0-596-00213-0.
[4]
Brumley, D. 1999. Invisible intruders: rootkits in practice. USENIX login.
[5]
Cowan, C., Pu, C., et al. 1998. StackGuard: Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks. In Proc. of the 7th USENIX Security Symposium.
[6]
Gross, G. 2009. Cybercriminals Can Shut Down U.S. Electrical Grid. http://www.cio.com/article/488716/Cybercriminals_Can_Sh ut_Down_U.S._Electrical_Grid
[7]
Hultquist, S. 2007. Rootkits: The next big enterprise threat? http://www.infoworld.com/d/security-central/rootkits-next-big-enterprise-threat-781
[8]
Kwiatek, L. and Litawa, S. 2008. Yet another Rustock analysis... Virus Bulletin.
[9]
Petroni, N. and Hicks, M. 2007. Automated Detection of Persistent Kernel Control-Flow Attacks. In Proc. of the 14th ACM Conference on Comp. and Comm. Security.
[10]
Phrack Inc. 2002. Writing Linux Kernel Keylogger. Phrack Volume 0x0b, Issue 0x3b, Phile #0x0e of 0x12.
[11]
Seshadri, A., Luk, M., Qu, N., and Perrig, A. 2007.SecVisor: A tiny hypervisor to provide lifetime kernel code integrity for commodity OSes. In Proceedings of SOSP.
[12]
Wei, J., Payne, B. D., Giffin, J., and Pu, C. 2008. Soft-timer driven transient kernel control flow attacks and defense. In Proceedings of the 24th Annual Computer Security Applications Conference (ACSAC).

Recommendations

Comments

Information & Contributors

Information

Published In

cover image ACM Other conferences
CSIIRW '11: Proceedings of the Seventh Annual Workshop on Cyber Security and Information Intelligence Research
October 2011
18 pages
ISBN:9781450309455
DOI:10.1145/2179298
Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

Sponsors

  • Eurosis: Eurosis
  • Oak Ridge National Laboratory
  • University of Tennessee: University of Tennessee

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 12 October 2011

Permissions

Request permissions for this article.

Check for updates

Qualifiers

  • Research-article

Conference

CSIIRW '11
Sponsor:
  • Eurosis
  • University of Tennessee

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • 0
    Total Citations
  • 111
    Total Downloads
  • Downloads (Last 12 months)1
  • Downloads (Last 6 weeks)0
Reflects downloads up to 04 Oct 2024

Other Metrics

Citations

View Options

Get Access

Login options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

Media

Figures

Other

Tables

Share

Share

Share this Publication link

Share on social media