A Software Detection Mechanism Based on SMM in Network Computing

被引:2
|
作者
Zhou, Lei [1 ]
Shu, Yang [1 ]
Wang, Guojun [2 ]
机构
[1] Cent S Univ, Sch Informat Sci & Engn, Changsha 410083, Hunan, Peoples R China
[2] Guangzhou Univ, Sch Comp Sci & Educ Software, Guangzhou 510006, Guangdong, Peoples R China
关键词
Software detection; Memory forensics; SMM; Semantic gap; Security agent; ROOTKIT;
D O I
10.1007/978-3-319-49145-5_14
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
To guarantee the network computing system security, the effective method is illegal or malicious software detection. Most of the former researches implement it on OS kernel or hypervisor level. However, if the system is attacked by the ring 0 or ring 1 level risks, the OS kernel or hypervisor is unable to provide the trusted base, which may cause an incorrect result. To solve the shortcomings, we choose the System Management Mode (SMM) to build a trusted execution environment. The SMM is a special cpu mode in the x86 architecture, which could create a security and isolated area on firmware level for malicious attacks detection. In this paper, we remotely interrupt the local system, and design a secure module in SMM to obtain messages from registers and physical memory space. Those messages are used to back analyze the software executing code segment for further information comparing. Beside the local detection, we use remote attestation approach for verifying the secure module. Our approach resists the attack surface under the OS level, and advances state-of-the-art detecting transparently. Furthermore, the analysis process could implement in the server to reduce the overheads on the client platform.
引用
收藏
页码:134 / 143
页数:10
相关论文
共 50 条
  • [1] Edge computing and AIoT based network intrusion detection mechanism
    Sui, Qingru
    Liu, Xiaoyan
    INTERNET TECHNOLOGY LETTERS, 2023, 6 (05)
  • [2] An Offloading Mechanism Based on Software Defined Network and Mobile Edge Computing in Vehicular Networks
    Zhang Haibo
    Jing Kunlun
    Liu Kaijian
    He Xiaofan
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2020, 42 (03) : 645 - 652
  • [3] An Offloading Mechanism Based on Software Defined Network and Mobile Edge Computing in Vehicular Networks
    Zhang H.
    Jing K.
    Liu K.
    He X.
    Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2020, 42 (03): : 645 - 652
  • [4] An In-Network Computing Service Placement Mechanism for NUMA-based Software Router
    Liang, Bowen
    Tian, Jianye
    Zhu, Yi
    EMERGING NETWORKING ARCHITECTURE AND TECHNOLOGIES, ICENAT 2022, 2023, 1696 : 3 - 12
  • [5] A novel approach for software vulnerability detection based on advanced computing
    Cho Do Xuan
    Huynh Nhat Anh
    Neural Computing and Applications, 2025, 37 (6) : 5121 - 5139
  • [6] A New Framework for Software Vulnerability Detection Based on an Advanced Computing
    Cong, Bui Van
    Xuan, Cho Do
    CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 79 (03): : 3699 - 3723
  • [7] DDoS Defense Mechanism Based on Software Defined Network
    Wang, Qian
    Zhao, Zhifeng
    Zhang, Honggang
    2017 IEEE 9TH INTERNATIONAL CONFERENCE ON COMMUNICATION SOFTWARE AND NETWORKS (ICCSN), 2017, : 1122 - 1127
  • [8] A NOVEL INTRUSION DETECTION MECHANISM IN CLOUD COMPUTING ENVIRONMENTS BASED ON ARTIFICIAL NEURAL NETWORK AND GENETIC ALGORITHM
    Ge, Ziheng
    Jiang, Guiyan
    Telecommunications and Radio Engineering (English translation of Elektrosvyaz and Radiotekhnika), 2024, 83 (12): : 51 - 64
  • [9] A network intrusion detection system based soft computing
    Liao, Niandong
    Tian, Shengfeng
    Huang, Houkuan
    Wang, Tinghua
    PROCEEDINGS OF THE FIRST INTERNATIONAL SYMPOSIUM ON DATA, PRIVACY, AND E-COMMERCE, 2007, : 517 - 519
  • [10] Software engineering issues for network computing
    Ghezzi, C
    INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE, PROCEEDINGS, 1997, : 2 - 2