Hypervisor-Based Active Data Protection for Integrity and Confidentiality of Dynamically Allocated Memory in Windows Kernel

05/30/2018
by   Igor Korkin, et al.
0

One of the main issues in the OS security is providing trusted code execution in an untrusted environment. During executing, kernel-mode drivers dynamically allocate memory to store and process their data: Windows core kernel structures, users' private information, and sensitive data of third-party drivers. All this data can be tampered with by kernel-mode malware. Attacks on Windows-based computers can cause not just hiding a malware driver, process privilege escalation, and stealing private data but also failures of industrial CNC machines. Windows built-in security and existing approaches do not provide the integrity and confidentiality of the allocated memory of third-party drivers. The proposed hypervisor-based system (AllMemPro) protects allocated data from being modified or stolen. AllMemPro prevents access to even 1 byte of allocated data, adapts for newly allocated memory in real time, and protects the driver without its source code. AllMemPro works well on newest Windows 10 1709 x64.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/24/2018

Divide et Impera: MemoryRanger Runs Drivers in Isolated Kernel Spaces

One of the main issues in the OS security is to provide trusted code exe...
research
01/22/2016

HyBIS: Windows Guest Protection through Advanced Memory Introspection

Effectively protecting the Windows OS is a challenging task, since most ...
research
05/13/2018

Shattered Trust: When Replacement Smartphone Components Attack

Phone touchscreens, and other similar hardware components such as orient...
research
10/06/2022

Microsoft Defender Will Be Defended: MemoryRanger Prevents Blinding Windows AV

Windows OS is facing a huge rise in kernel attacks. An overview of popul...
research
06/10/2021

Windows Kernel Hijacking Is Not an Option: MemoryRanger Comes to the Rescue Again

The security of a computer system depends on OS kernel protection. It is...
research
04/29/2019

Technical Report: A Toolkit for Runtime Detection of Userspace Implants

This paper presents the Userspace Integrity Measurement Toolkit (USIM To...
research
02/20/2018

A Reliable and Practical Approach to Kernel Attack Surface Reduction of Commodity OS

Commodity OS kernels are known to have broad attack surfaces due to the ...

Please sign up or login with your details

Forgot password? Click here to reset