Matches in SemOpenAlex for { <https://semopenalex.org/work/W2104730023> ?p ?o ?g. }
Showing items 1 to 73 of
73
with 100 items per page.
- W2104730023 abstract "Recent rootkit-attack mitigation work neglected to address the integrity of the mitigation tool itself. Both detection and prevention arms of current rootkit-attack mitigation solutions can be given credit for the advancement of multiple methodologies for rootkit defense but if the defense system itself is compromised, how is the defense system to be trusted? Another deficiency not addressed is how platform integrity can be preserved without availability of current RIDS or RIPS solutions, which operate only upon the loading of the kernel i.e. without availability of a trusted boot environment. To address these deficiencies, we present our architecture for solving rootkit persistence – Rootkit Guard (RG). RG is a marriage between TrustedGRUB (providing trusted boot), IMA (Integrity Measurement Architecture) (serves as RIDS) and SELinux (serves as RIPS). TPM hardware is utilised to provide total integrity of our platform via storage of the aggregate of the clean snapshot of our platform OS kernel into TPM hardware registers (i.e. the PCR) – of which no software attacks have been demonstrated to date. RG solves rootkit persistence by leveraging on one vital but simple strategy: the mounting of rootkit defense via prevention of the execution of configuration binaries or build initialisation scripts. We adopted the technique of rootkit persistence prevention via thwarting the initialisation of a rootkit’s installation procedure; if the rootkit is successfully installed, proper deployment via thwarting of the rootkit’s configuration is prevented. We had subjected the RG to 8 real world Linux 2.6 rootkits and the RG was successful in solving rootkit persistence in all 8 evaluated rootkits. In terms of performance, the RG introduced a maximum of 11% overhead and an average of 4% overhead, hence permitting deployment in production environments." @default.
- W2104730023 created "2016-06-24" @default.
- W2104730023 creator A5026258736 @default.
- W2104730023 creator A5035208215 @default.
- W2104730023 creator A5083341742 @default.
- W2104730023 creator A5087113469 @default.
- W2104730023 date "2013-01-01" @default.
- W2104730023 modified "2023-09-26" @default.
- W2104730023 title "Rootkit Guard (RG) - an architecture for rootkit resistant file-system implementation based on TPM" @default.
- W2104730023 cites W103986934 @default.
- W2104730023 cites W1504669610 @default.
- W2104730023 cites W1656731780 @default.
- W2104730023 cites W1976956141 @default.
- W2104730023 cites W1979897749 @default.
- W2104730023 cites W2002233360 @default.
- W2104730023 cites W2023824732 @default.
- W2104730023 cites W2029224396 @default.
- W2104730023 cites W2059063827 @default.
- W2104730023 cites W2110756602 @default.
- W2104730023 cites W2125883665 @default.
- W2104730023 cites W2167804035 @default.
- W2104730023 hasPublicationYear "2013" @default.
- W2104730023 type Work @default.
- W2104730023 sameAs 2104730023 @default.
- W2104730023 citedByCount "0" @default.
- W2104730023 crossrefType "journal-article" @default.
- W2104730023 hasAuthorship W2104730023A5026258736 @default.
- W2104730023 hasAuthorship W2104730023A5035208215 @default.
- W2104730023 hasAuthorship W2104730023A5083341742 @default.
- W2104730023 hasAuthorship W2104730023A5087113469 @default.
- W2104730023 hasConcept C10144332 @default.
- W2104730023 hasConcept C111919701 @default.
- W2104730023 hasConcept C141141315 @default.
- W2104730023 hasConcept C199360897 @default.
- W2104730023 hasConcept C202775310 @default.
- W2104730023 hasConcept C38652104 @default.
- W2104730023 hasConcept C41008148 @default.
- W2104730023 hasConcept C541664917 @default.
- W2104730023 hasConceptScore W2104730023C10144332 @default.
- W2104730023 hasConceptScore W2104730023C111919701 @default.
- W2104730023 hasConceptScore W2104730023C141141315 @default.
- W2104730023 hasConceptScore W2104730023C199360897 @default.
- W2104730023 hasConceptScore W2104730023C202775310 @default.
- W2104730023 hasConceptScore W2104730023C38652104 @default.
- W2104730023 hasConceptScore W2104730023C41008148 @default.
- W2104730023 hasConceptScore W2104730023C541664917 @default.
- W2104730023 hasLocation W21047300231 @default.
- W2104730023 hasOpenAccess W2104730023 @default.
- W2104730023 hasPrimaryLocation W21047300231 @default.
- W2104730023 hasRelatedWork W118544037 @default.
- W2104730023 hasRelatedWork W1565457235 @default.
- W2104730023 hasRelatedWork W1598700299 @default.
- W2104730023 hasRelatedWork W1972479252 @default.
- W2104730023 hasRelatedWork W1972680844 @default.
- W2104730023 hasRelatedWork W2078661549 @default.
- W2104730023 hasRelatedWork W2103042869 @default.
- W2104730023 hasRelatedWork W2120118950 @default.
- W2104730023 hasRelatedWork W2275408761 @default.
- W2104730023 hasRelatedWork W2352764394 @default.
- W2104730023 hasRelatedWork W2353907366 @default.
- W2104730023 hasRelatedWork W2382524278 @default.
- W2104730023 hasRelatedWork W2791053487 @default.
- W2104730023 hasRelatedWork W3021659635 @default.
- W2104730023 hasRelatedWork W3083181304 @default.
- W2104730023 hasRelatedWork W3191081123 @default.
- W2104730023 hasRelatedWork W3208020858 @default.
- W2104730023 hasRelatedWork W406878325 @default.
- W2104730023 hasRelatedWork W437117608 @default.
- W2104730023 hasRelatedWork W2828238390 @default.
- W2104730023 isParatext "false" @default.
- W2104730023 isRetracted "false" @default.
- W2104730023 magId "2104730023" @default.
- W2104730023 workType "article" @default.