KQguard: Protecting Kernel Callback Queues
Jinpeng Wei, Feng Zhu, Calton Pu · 2012
Kernel callback queues (KQs) are the mechanism of choice for handling events in modern kernels. KQs have been misused by real-world malware to get a kernel thread to run malicious code. Current defense mechanisms for kernel code and data integrity have difficulties with KQ attacks, since they work without necessarily changing legitimate kernel code or data. In this paper, we describe the design, implementation, and evaluation of KQguard, an efficient and effective protection mechanism of KQs. KQguard uses static and dynamic analysis of kernel and device drivers to learn the legitimate event handlers. At runtime, KQguard rejects all the unknown KQ requests that cannot be validated. We implemented KQguard on Windows Research Kernel (WRK) and extensive experimental evaluation shows KQguard is efficient (up to 5% overhead) and effective (capable of achieving zero false positives and false negatives against 11 real malware and 9 synthetic attacks). KQguard protects all the 20 KQs in WRK, can be extended to accommodate new device drivers, and through dynamic analysis can support closed source device drivers.