Back to Search
Start Over
Operating systems support for process dynamic integrity measurement
- Source :
- 2009 IEEE Youth Conference on Information, Computing and Telecommunication.
- Publication Year :
- 2009
- Publisher :
- IEEE, 2009.
-
Abstract
- Facing limitations of existing systems for process integrity measurement, we put forward a method with its prototype system PDIMS to measure process runtime integrity. Based on structure of process and format of executable file, PDIMS anatomizes the codepage layout of runtime process. Combining OS mechanisms and modern CPU's support for code execution, PDIMS catches and measures codepage in the kernel when it executes. PDIMS depends on CPU's non-executable bit to detect code execution and on the binary format of executables of the process as criterion to verify code modifications in kernel. PDIMS provides trustworthy information about whether a running process is modified. PDIMS introduces less than 4% overhead to OS.
Details
- Database :
- OpenAIRE
- Journal :
- 2009 IEEE Youth Conference on Information, Computing and Telecommunication
- Accession number :
- edsair.doi...........10c0d1c4d7c321f54207df26faf56def
- Full Text :
- https://doi.org/10.1109/ycict.2009.5382352