The search functionality is under construction.

IEICE TRANSACTIONS on Communications

Open Access
Detecting and Guarding against Kernel Backdoors through Packet Flow Differentials

Cheolho LEE, Kiwook SOHN

  • Full Text Views

    26

  • Cite this
  • Free PDF (682.2KB)

Summary :

In this paper, we present a novel technique to detect and defeat kernel backdoors which cannot be identified by conventional security solutions. We focus on the fact that since the packet flows of common network applications go up and down through the whole network subsystem but kernel backdoors utilize only the lower layers of the subsystem, we can detect kernel backdoors by employing two host-based monitoring sensors (one at higher layer and the other at lower layer) and by inspecting the packet flow differentials. We also provide strategies to mitigate false positives and negatives and to defeat kernel backdoors. To evaluate the effectiveness of the proposed technique, we implemented a detection system (KbGuard) and performed experiments in a simulated environment. The evaluation results indicate that our approach can effectively detect and deactivate kernel backdoors with a high detection rate. We also believe that our research can help prevent stealthy threats of kernel backdoors.

Publication
IEICE TRANSACTIONS on Communications Vol.E90-B No.10 pp.2638-2645
Publication Date
2007/10/01
Publicized
Online ISSN
1745-1345
DOI
10.1093/ietcom/e90-b.10.2638
Type of Manuscript
Special Section PAPER (Special Section on New Challenge for Internet Technology and its Architecture)
Category

Authors

Keyword