首页> 外文OA文献 >JoKER: Trusted Detection of Kernel Rootkits in Android Devices via JTAG Interface
【2h】

JoKER: Trusted Detection of Kernel Rootkits in Android Devices via JTAG Interface

机译:JoKER:通过JTaG可靠地检测android设备中的内核Rootkit   接口

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Smartphones and tablets have become prime targets for malware, due to thevaluable private and corporate information they hold. While Anti-Virus (AV)program may successfully detect malicious applications (apps), they remainineffective against low-level rootkits that evade detection mechanisms bymasking their own presence. Furthermore, any detection mechanism run on thesame physical device as the monitored OS can be compromised via application,kernel or boot-loader vulnerabilities. Consequentially, trusted detection ofkernel rootkits in mobile devices is a challenging task in practice. In thispaper we present JoKER - a system which aims at detecting rootkits in theAndroid kernel by utilizing the hardware's Joint Test Action Group (JTAG)interface for trusted memory forensics. Our framework consists of componentsthat extract areas of a kernel's memory and reconstruct it for furtheranalysis. We present the overall architecture along with its implementation,and demonstrate that the system can successfully detect the presence ofstealthy rootkits in the kernel. The results show that although JTAG's mainpurpose is system testing, it can also be used for malware detection wheretraditional methods fail.
机译:智能手机和平板电脑由于拥有宝贵的私人和公司信息,已成为恶意软件的主要攻击目标。尽管防病毒(AV)程序可以成功检测到恶意应用程序,但它们对低级rootkit仍然无效,后者通过掩盖自身的存在来逃避检测机制。此外,可以通过应用程序,内核或引导加载程序漏洞来破坏与受监控的操作系统在同一物理设备上运行的任何检测机制。因此,在实践中,对移动设备中的内核rootkit进行可靠的检测是一项艰巨的任务。在本文中,我们介绍了JoKER-一种旨在通过利用硬件的联合测试操作组(JTAG)接口进行可信内存取证来检测Android内核中的rootkit的系统。我们的框架由提取内核内存区域并对其进行重构以供进一步分析的组件组成。我们介绍了整个体系结构及其实现,并演示了该系统可以成功检测内核中隐身rootkit的存在。结果表明,尽管JTAG的主要用途是系统测试,但它也可以用于传统方法失败的恶意软件检测。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号