A Software Detection Mechanism Based on SMM in Network Computing

被引:2
|
作者
Zhou, Lei [1 ]
Shu, Yang [1 ]
Wang, Guojun [2 ]
机构
[1] Cent S Univ, Sch Informat Sci & Engn, Changsha 410083, Hunan, Peoples R China
[2] Guangzhou Univ, Sch Comp Sci & Educ Software, Guangzhou 510006, Guangdong, Peoples R China
关键词
Software detection; Memory forensics; SMM; Semantic gap; Security agent; ROOTKIT;
D O I
10.1007/978-3-319-49145-5_14
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
To guarantee the network computing system security, the effective method is illegal or malicious software detection. Most of the former researches implement it on OS kernel or hypervisor level. However, if the system is attacked by the ring 0 or ring 1 level risks, the OS kernel or hypervisor is unable to provide the trusted base, which may cause an incorrect result. To solve the shortcomings, we choose the System Management Mode (SMM) to build a trusted execution environment. The SMM is a special cpu mode in the x86 architecture, which could create a security and isolated area on firmware level for malicious attacks detection. In this paper, we remotely interrupt the local system, and design a secure module in SMM to obtain messages from registers and physical memory space. Those messages are used to back analyze the software executing code segment for further information comparing. Beside the local detection, we use remote attestation approach for verifying the secure module. Our approach resists the attack surface under the OS level, and advances state-of-the-art detecting transparently. Furthermore, the analysis process could implement in the server to reduce the overheads on the client platform.
引用
收藏
页码:134 / 143
页数:10
相关论文
共 50 条
  • [41] Adaptive Computing Optimization in Software-Defined Network-Based Industrial Internet of Things with Fog Computing
    Wang, Juan
    Li, Di
    SENSORS, 2018, 18 (08)
  • [42] Probabilistic Caching Mechanism Based on Software Defined Content Centric Network
    Gao, Yanyu
    Zhou, Jinhe
    2019 IEEE 11TH INTERNATIONAL CONFERENCE ON COMMUNICATION SOFTWARE AND NETWORKS (ICCSN 2019), 2019, : 210 - 214
  • [43] Software-Based Mechanism for Network-on-Chip Performance Increase
    Linck, Marcelo
    Paz, Gabriel
    Santos, Augusto
    Marcon, Cesar
    23RD IEEE INTERNATIONAL CONFERENCE ON ELECTRONICS CIRCUITS AND SYSTEMS (ICECS 2016), 2016, : 628 - 631
  • [44] MADRLOM: A Computation offloading mechanism for software-defined cloud-edge computing power network
    Guo, Yinzhi
    Xu, Xiaolong
    Xiao, Fu
    COMPUTER NETWORKS, 2024, 245
  • [45] A Network Misuse Detection Mechanism Based on Traffic Log
    Yang, Yahui
    Huang, Chunfang
    Qin, Zhijing
    NSWCTC 2009: INTERNATIONAL CONFERENCE ON NETWORKS SECURITY, WIRELESS COMMUNICATIONS AND TRUSTED COMPUTING, VOL 1, PROCEEDINGS, 2009, : 526 - 529
  • [46] Selective forwarding attack detection and network recovery mechanism based on cloud-edge cooperation in software-defined wireless sensor network
    Luo, Shiyao
    Lai, Yingxu
    Liu, Jing
    COMPUTERS & SECURITY, 2023, 126
  • [47] Cyber-Physical Systems Testbed Based on Cloud Computing and Software Defined Network
    Gao, Haihui
    Peng, Yong
    Wen, Zhe
    Jia, Kebin
    Li, Hanjing
    2015 INTERNATIONAL CONFERENCE ON INTELLIGENT INFORMATION HIDING AND MULTIMEDIA SIGNAL PROCESSING (IIH-MSP), 2015, : 337 - 340
  • [48] Design of the Network Security Intrusion Detection System Based on the Cloud Computing
    Di, Meng
    CYBER SECURITY INTELLIGENCE AND ANALYTICS, 2020, 928 : 68 - 73
  • [49] Software Testing Based on Cloud Computing
    Jun, Wang
    Meng, Fanpeng
    2010 THE 3RD INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND INDUSTRIAL APPLICATION (PACIIA2010), VOL II, 2010, : 409 - 412
  • [50] A software bus based on the grid computing
    Cheng, YB
    DCABES 2004, Proceedings, Vols, 1 and 2, 2004, : 40 - 42