首页> 美国政府科技报告 >Taxonomy of Software Deceptive Interpretation in the Linux Operating System
【24h】

Taxonomy of Software Deceptive Interpretation in the Linux Operating System

机译:Linux操作系统中软件欺骗性解释的分类

获取原文

摘要

Rootkits are malicious tools installed on compromised computer systems that help intruders take advantage of and maintain unauthorized access. Modern rootkits routinely employ deceptive interpretation to evade detection. This allows them to remain hidden and operational for extended periods of time, drastically prolonging and escalating the damage from the system compromise. This report investigates the concept of deceptive interpretation in order to explore high assurance approaches to detect rootkits. A taxonomy was developed through a systematic analysis of the Linux operating system that enumerates all possible mechanisms of performing software deceptive interpretation. Many novel mechanisms, not yet implemented in published rootkits, were discovered and included in the taxonomy. Categorization was based on the system objects that need to be modified for the deceptive interpretation mechanism. As a result, detectors that target the set of system objects associated with a category will be able to detect all deceptive interpreters in that category including previously unknown implementations. This work can serve as the basis for developing an alternative to the signature-based approach with the capability to provide categorical protection against deceptive interpreters and rootkits.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号