Back to Search View Original Cite This Article

Abstract

<jats:p>The monograph is devoted to solving one of the most pressing information security problems — protecting the Windows kernel from complex low-level threats. The research was carried out in two interrelated directions: protecting the kernel memory from manipulation by drivers and detecting hidden hypervisors using hardware virtualization technology. An analysis of the evolution of rootkit techniques and OS defense mechanisms shows that many attacks on the kernel are not detected in practice by standard security tools, including Kernel Patch Protection (PatchGuard). In response to these challenges, the author suggests two complementary approaches. The first is hypervisor core memory protection, implemented in the solutions MemoryMonRWX, AllMemPro and MemoryRanger. These systems use Intel VT-x and EPT to run drivers in isolated enclaves and to monitor memory accesses. The second approach is aimed at identifying hidden hypervisors using statistical analysis of the characteristics of the duration of instructions. The proposed technique makes it possible to detect such threats even with active opposition from the violator. The work is based on the author's many years of research, reflected in his numerous scientific publications, patents and reports at international conferences. For information security specialists, teachers, students, and graduate students. The book will also be useful for developers and experts involved in analyzing malicious software and creating information security systems for operating systems.</jats:p>

Show More

Keywords

security kernel information from memory

Related Articles

PORE

About

Connect