Mapping kernel objects to enable systematic integrity checking

Martim Carbone, Weidong Cui, Long Jason Lu, Wenke Lee, Marcus Peinado, Xuxian Jiang · 2009

Dynamic kernel data have become an attractive target for kernel-mode malware. However, previous solutions for checking kernel integrity either limit themselves to code and static data or can only inspect a fraction of dynamic data, resulting in limited protection. Our study shows that previous solutions may reach only 28% of the dynamic kernel data and thus may fail to identify function pointers manipulated by many kernel-mode malware.

Read the paper · More papers on PaperTik