Feeds

Boffins boast newfangled rootkit blocker

Large scale, low overhead

Providing a secure and efficient Helpdesk

Scientists are set to unveil a lightweight system they say makes an operating system significantly more resistant to rootkits without degrading its performance.

The hypervisor-based system is dubbed HookSafe, and it works by relocating kernel hooks in a guest OS to a dedicated page-aligned memory space that's tightly locked down. The researchers, from Microsoft and the computer science department at North Carolina State University, plan to present their findings Thursday at the 16th ACM Conference on Computer and Communications Security.

The team installed HookSafe on a machine running Ubuntu 8.04, and found the system successfully prevented nine real-world rootkits targeting that platform from installing or hiding themselves. The program was able to achieve that protection with only a 6-percent reduction in performance benchmarks, making HookSafe "the first system that is proposed to enable large-scale hook protection with low performance overhead," the researchers said.

Rootkits that rely on a method known as kernel object hooking involve modifying kernel data hooks. Because they are scattered throughout the operating system memory, and often co-mingled with other kernel data, they are generally hard to protect. Scientists have dubbed the problem the "protection granularity gap" because effective protection requires byte-level granularity while commodity computers allow only for protection at the much broader page level.

The researchers worked around this limitation by relocating almost 5,900 kernel hooks scattered across 41 physical pages to a page-aligned central location. They then used a "thin hook indirection layer to regulate accesses to them with hardware-based page-level protection."

They tested the protected system against nine rootkits written for the Linux 2.6 kernel. Seven of them failed to install at all thanks to the memory protection, while the remaining two failed to hide themselves because of the hook indirection.

The researchers are Zhi Wang, Xuxian Jiang and Peng Ning of North Carolina State University and Weidong Cui of Microsoft Research. A PDF of their paper is available here. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
Hackers thrash Bash Shellshock bug: World races to cover hole
Update your gear now to avoid early attacks hitting the web
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.