Detecting and Preventing Kernel Rootkit Attacks with Bus Snooping
Hyungon Moon, Hojoon Lee, Ingoo Heo, Kihwan Kim, Yunheung Paek, Brent Byunghoon Kang · IEEE Transactions on Dependable and Secure Computing · 2015
To protect the integrity of operating system kernels, we presentVigilare system, a kernel integrity monitor that is architected to snoop the bus traffic of the host system from a separate independent hardware. Thissnoop-based monitoringenabled by the Vigilare system, overcomes the limitations of thesnapshot-based monitoringemployed in previous kernel integrity monitoring solutions. Being based on inspecting snapshots collected over a certain interval, the previous hardware-based monitoring solutions cannot detecttransient attacksthat can occur in between snapshots, and cannot protect the kernel against permanent damage. We implemented three prototypes of the Vigilare system by addingSnooperhardware connections module to the host system for bus snooping, and a snapshot-based monitor to be comared with, in order to evaluate the benefit of snoop-based monitoring. The prototypes of Vigilare system detected all the transient attacks and the second one protected the kernel with negligible performance degradation while the snapshot-based monitor could not detect all the attacks and induced considerable performance degradation as much as 10 percent in our tuned STREAM benchmark test.