Rootkits and the OS friendly microprocessor architecture

Patrick W. Jungwirth, Thomas Barnett, Abdel‐Hameed A. Badawy · Proceedings of SPIE, the International Society for Optical Engineering/Proceedings of SPIE · 2017

We examine how the hardware level security features in the OS Friendly Microprocessor Architecture improves cybersecurity against a rootkit attack. A rootkit (root + kit) is a malicious program or tool -“kit” of programs designed to obtain “root” level privileges (root for Unix, admin for Windows). Rootkits operate at the same security ring level as an operating system. This gives rootkits access to kernel level data structures. Even with state-of-the-art security technologies, it is very difficult to detect a rootkit. Rootkits have been used for digital rights management and copy protection; however, the 2005 CD copy protection scandal illustrates how poor computer security can leave an open door for other malware. We present a security model of the OS Friendly Microprocessor Architecture and we present a short introduction to rootkits. For this paper, we will focus on OS-kernel level rootkits. We will illustrate how the hardware security features of the OS Friendly Microprocessor Architecture increases the difficulty for rootkit malware to compromise a computer system.

Read the paper · More papers on PaperTik