Jump to content
Nytro

DETECT KERNEL - MODE ROOTKITS VIA RE AL TIME LOGGING & CONTROLLIN G MEMORY ACCESS

Recommended Posts

ABSTRACT


Modern malware and spyware platforms attack existing antivirus solutions and even Microsoft PatchGuard.
To protect users and business systems new technologies developed by Intel and AMD CPUs may be
applied. To deal with the new malware we propose monitoring and controlling access to the memory in real
time using Intel VT-x with EPT. We have checked this concept by developing MemoryMonRWX, which is
a bare-metal hypervisor. MemoryMonRWX is able to track and trap all types of memory access: read,
write, and execute. MemoryMonRWX also has the following competitive advantages: fine-grained analysis,
support of multi-core CPUs and 64-bit Windows 10. MemoryMonRWX is able to protect critical kernel
memory areas even when PatchGuard has been disabled by malware. Its main innovative features are as
follows: guaranteed interception of every memory access, resilience, and low performance degradation.

 

Download: https://arxiv.org/ftp/arxiv/papers/1705/1705.06784.pdf

  • Upvote 1
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...