Technical Report: A Toolkit for Runtime Detection of Userspace Implants

04/29/2019
by   J. Aaron Pendergrass, et al.
0

This paper presents the Userspace Integrity Measurement Toolkit (USIM Toolkit), a set of integrity measurement collection tools capable of detecting advanced malware threats, such as memory-only implants, that evade many traditional detection tools. Userspace integrity measurement validates that a platform is free from subversion by validating that the current state of the platform is consistent with a set of invariants. The invariants enforced by the USIM Toolkit are carefully chosen based on the expected behavior of userspace, and key behaviors of advanced malware. Userspace integrity measurement may be combined with existing filesystem and kernel integrity measurement approaches to provide stronger guarantees that a platform is executing the expected software and that the software is in an expected state.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/09/2018

EPA-RIMM: A Framework for Dynamic SMM-based Runtime Integrity Measurement

Runtime integrity measurements identify unexpected changes in operating ...
research
08/08/2022

Simple Rigs Hold Fast

An important use of computational systems is updating the state of an ob...
research
11/25/2019

JSLess: A Tale of a Fileless Javascript Memory-Resident Malware

New computing paradigms, modern feature-rich programming languages and o...
research
03/29/2019

BootKeeper: Validating Software Integrity Properties on Boot Firmware Images

Boot firmware, like UEFI-compliant firmware, has been the target of nume...
research
05/30/2018

Hypervisor-Based Active Data Protection for Integrity and Confidentiality of Dynamically Allocated Memory in Windows Kernel

One of the main issues in the OS security is providing trusted code exec...
research
02/04/2021

Challenges in biomarker discovery and biorepository for Gulf-war-disease studies: a novel data platform solution

Aims: Our Gulf War Illness (GWI) study conducts combinatorial screening ...
research
05/20/2020

Tracking Measurement Obfuscations from SourceURL

Tracking scripts can use the sourceURL directive to mask their origin fr...

Please sign up or login with your details

Forgot password? Click here to reset