Detecting eBPF Rootkits Using Virtualization and Memory Forensics

Nezer Jacob Zaidenberg, Michael Kiperberg, Eliav Menachi, Asaf Eitani

نتاج البحث: فصل من :كتاب / تقرير / مؤتمرمنشور من مؤتمرمراجعة النظراء

ملخص

There is a constant increase in the sophistication of cyber threats. Areas considered immune to malicious code, such as eBPF, are shown to be perfectly suitable for malware. Initially, the eBPF mechanism was devised to inject small programs into the kernel, assisting in network routing and filtering. Recently, it was demonstrated that malicious eBPF programs can be used to construct rootkits. The previously proposed countermeasures need to be revised against rootkits that attempt to hide their presence. We propose a novel detection scheme that divides the detection process into two phases. In the first phase, the memory image of the potentially infected system is acquired using a hypervisor. In the second phase, the image is analyzed. The analysis includes extraction and classification of the eBPF programs. The classifier’s decision is based on the set of helper functions used by each eBPF program. Our study revealed a set of helper functions used only by malicious eBPF programs. The proposed scheme achieves optimal precision while suffering only a minor performance penalty for each additional eBPF program.

اللغة الأصليةالإنجليزيّة
عنوان منشور المضيفProceedings of the 10th International Conference on Information Systems Security and Privacy
المحررونGabriele Lenzini, Paolo Mori, Steven Furnell
ناشرScience and Technology Publications, Lda
الصفحات254-261
عدد الصفحات8
رقم المعيار الدولي للكتب (المطبوع)9789897586835
المعرِّفات الرقمية للأشياء
حالة النشرنُشِر - 2024
الحدث10th International Conference on Information Systems Security and Privacy, ICISSP 2024 - Rome, إيطاليا
المدة: ٢٦ فبراير ٢٠٢٤٢٨ فبراير ٢٠٢٤

سلسلة المنشورات

الاسمInternational Conference on Information Systems Security and Privacy
مستوى الصوت1
رقم المعيار الدولي للدوريات (الإلكتروني)2184-4356

!!Conference

!!Conference10th International Conference on Information Systems Security and Privacy, ICISSP 2024
الدولة/الإقليمإيطاليا
المدينةRome
المدة٢٦/٠٢/٢٤٢٨/٠٢/٢٤

بصمة

أدرس بدقة موضوعات البحث “Detecting eBPF Rootkits Using Virtualization and Memory Forensics'. فهما يشكلان معًا بصمة فريدة.

قم بذكر هذا