谷歌浏览器插件
订阅小程序
在清言上使用

Copilot - a coprocessor-based kernel runtime integrity monitor

SSYM'04 Proceedings of the 13th conference on USENIX Security Symposium - Volume 13(2004)

引用 0|浏览1
暂无评分
摘要
Copilot is a coprocessor-based kernel integrity monitor for commodity systems. Copilot is designed to detect malicious modifications to a host's kernel and has correctly detected the presence of 12 real-world rootkits, each within 30 seconds of their installation with less than a 1% penalty to the host's performance. Copilot requires no modifications to the protected host's software and can be expected to operate correctly even when the host kernel is thoroughly compromised - an advantage over traditional monitors designed to run on the host itself.
更多
查看译文
关键词
host kernel,protected host,coprocessor-based kernel integrity monitor,commodity system,malicious modification,real-world rootkits,traditional monitor,coprocessor-based kernel runtime integrity
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要