...
首页> 外文期刊>Digital investigation >Leveraging relocations in ELF-binaries for Linux kernel version identification
【24h】

Leveraging relocations in ELF-binaries for Linux kernel version identification

机译:利用ELF二进制文件中的重定位来确定Linux内核版本

获取原文
获取原文并翻译 | 示例
           

摘要

Identification of operating system kernel version is essential in a large number of forensic and security applications in both cloud and local environments. Prior state-of-the-art uses complex differential analysis of several aspects of kernel implementation and knowledge of kernel data structures. In this paper, we present a working research prototype codeid-elf for ELF binaries based on its Windows counterpart codeid, which can identify kernels through relocation entries extracted from the binaries. We show that relocation-based signatures are unique and distinct and thus, can be used to accurately determine Linux kernel versions and derandomize the base address of the kernel in memory (when kernel Address Space Layout Randomization is enabled). We evaluate the effectiveness of codeid-elf on a subset of Linux kernels and find that the relocations in kernel code have nearly 100% code coverage and low similarity (uniqueness) across various kernels. Finally, we show that codeid-elf, which leverages relocations in kernel code, can detect all kernel versions in the test set with almost 100% page hit rate and nearly zero false negatives. (C) 2018 The Author(s). Published by Elsevier Ltd on behalf of DFRWS.
机译:在云和本地环境中,对于大量取证和安全应用程序而言,操作系统内核版本的标识至关重要。现有技术水平使用对内核实现的几个方面和内核数据结构的知识进行复杂的差异分析。在本文中,我们根据ELF二进制文件的Windows对应代码ID提出了一个可工作的研究原型codeid-elf,它可以通过从二进制文件中提取的重定位条目来识别内核。我们展示了基于重定位的签名是唯一且独特的,因此可以用于准确确定Linux内核版本并在内存中对内核的基地址进行随机化(启用内核地址空间布局随机化时)。我们评估了codeid-elf在Linux内核子集上的有效性,发现内核代码中的重定位具有近100%的代码覆盖率以及各个内核之间的相似度(唯一性)低。最后,我们表明利用内核代码中的重定位的codeid-elf可以检测到测试集中的所有内核版本,其页面命中率几乎为100%,假阴性率几乎为零。 (C)2018作者。由Elsevier Ltd代表DFRWS发布。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号