Novel approach for protecting integrity of kernel based on reference monitor

Tian Rong-hua · Journal of Computer Applications · 2006

With concept of reference monitor and function of virtual machine monitor, a novel approach for protecting integrity of kernel was designed. In the design, a virtual machine monitor was used as reference monitor by our adding reference monitor module into it. Guest operating system kernel runs on the top of the reference monitor as non-privileged mode. When the non-privileged kernel attempts to write some resources, it is mandatory for the writing permission to be verified and approved by the reference monitor running in privileged mode. So, it prevents malicious code from tampering the kernel. Compared to the traditional defense methods against malicious code, these traditional methods only can detect integrity of kernel, but not prevent it from tampering the kernel.

Read the paper · More papers on PaperTik