Self-signed executables: restricting replacement of program binaries by malware
Glenn Wurster, Paul C. van Oorschot · USENIX conference on Hot topics in security · 2007
We propose using digital signatures to protect binaries already on the system from modifications by malware. While applicable to any file which is not intended to be modified by an end user, we concentrate on protecting programs and libraries present on the system before infection. Our protection does not rely on a central trusted authority or PKI, and can be incrementally deployed. While presented in the context of the Linux environment, our approach applies to other operating systems such as Windows.