Maya: Hardware Enhanced Customizable Defenses at the User-Kernel Interface

Preet Derasari, Guru Venkataramani · 2024

In the dynamic landscape of digital threats, robust security measures must not only thwart malicious actors but also provide valuable insights into their tactics and mindset. In this context, the need for defenses that are both proactive and capable of engaging the adversaries becomes evident. These defenses are designed to adapt to evolving threats and provide a nuanced approach to computer system security. Proactive defenses, like honeypots and decoys, play a pivotal role in achieving these dual objectives by offering the ability to both protect systems and gather critical threat intelligence. This paper introduces Maya, a hardware design aimed at enhancing the efficiency of customizable defense systems that proactively counter computer security attacks, while also understanding the adversary's behavioral tactics. We propose a framework utilizing Maya to activate lightweight subroutines that dynamically influence the behavior of malicious programs at the user-kernel interface. By presenting an altered view of the system state to potential attackers, this framework safeguards sensitive resources and thwarts unauthorized access to intended targets. Leveraging the inherent efficiency of hardware, our framework ensures that its actions remain discreet, minimizing the risk of detection and disengagement by adversaries. We assess the effectiveness of Maya against several notorious attack vectors, including ransomware, info-stealers, and timing channels. Additionally, we scrutinize how a MAYA-enabled defense framework impacts legitimate applications that malware detection systems might incorrectly flag. Our evaluation reveals that Maya incurs minimal runtime overhead when handling kernel requests from a suspected process, highlighting an improved efficacy compared to software-based solutions.

Read the paper · More papers on PaperTik