Dynamic Monitoring of Malicious Activity in Software Systems

Mourad Debbabi, M. A. Girard, Luc Poulin, Martin Salois, Nadia Tawbi · 2000

Because of time and budget constraints, organisations are turning more and more to Commercial-Off-The-Shelf (COTS) software rather than developing in-house software. This situation gives rise to great concerns over safety, security, and reliability in critical information systems. This paper presents a research effort to help manage the risk associated with COTS integration through the exploitation of a dynamic monitor. The strategy consists of inserting appropriate drivers to control accesses to critical resources: files, communication ports, the registry, and the creation/destruction of processes and threads. A prototype monitor called DaMon has been designed and developed to run in Windows NT on an Intel box, to demonstrate the feasibility of reactive monitoring to meet a formal security specification.

Read the paper · More papers on PaperTik