Skip to main navigation Skip to search Skip to main content

KI-Mon ARM: A Hardware-Assisted Event-triggered Monitoring Platform for Mutable Kernel Object

  • Hojoon Lee
  • , Hyungon Moon
  • , Ingoo Heo
  • , Daehee Jang
  • , Jinsoo Jang
  • , Kihwan Kim
  • , Yunheung Paek
  • , Brent Byunghoon Kang

Research output: Contribution to journalArticlepeer-review

12 Citations (Scopus)

Abstract

External hardware-based kernel integrity monitors have been proposed to mitigate kernel-level malwares. However, the existing external approaches have been limited to monitoring the static regions of kernel while the latest rootkits manipulate the dynamic kernel objects. To address the issue, we present KI-Mon, a hardware-based platform that introduces event-triggered monitoring techniques for kernel dynamic objects. KI-Mon advances the bus traffic snooping technique to not only detect memory write traffic on the host bus but also filter out all but meaningful traffic to generate events. We show how kernel invariant verification software can be developed around these events, and also provide a set of APIs for additional invariant verification development. We also report our findings and considerations on the unique challenges for external monitors-such as cache coherency, dynamic object tracing. We introduce host-side kernel changes that alleviate these issues that involve changes in kernel's object allocation and cache policy control. We have built a prototype of KI-Mon on the ARM architecture to demonstrate the efficacy of KI-Mon's event-triggered mechanism in terms of performance overhead for the monitored host system and the processor usage of the KI-Mon processor.

Original languageEnglish
Article number7874084
Pages (from-to)287-300
Number of pages14
JournalIEEE Transactions on Dependable and Secure Computing
Volume16
Issue number2
DOIs
Publication statusPublished - 1 Mar 2019

Bibliographical note

Publisher Copyright:
© 2004-2012 IEEE.

Keywords

  • Kernel security
  • hardware-based kernel monitoring
  • kernel integrity monitors
  • rootkit detection

Fingerprint

Dive into the research topics of 'KI-Mon ARM: A Hardware-Assisted Event-triggered Monitoring Platform for Mutable Kernel Object'. Together they form a unique fingerprint.

Cite this