Rootkit detection on embedded IoT devices

IoT systems are subject to cyber attacks, including infecting embedded IoT devices with rootkits. Rootkits are malicious software that typically run with elevated privileges, which makes their detection challenging. In this paper, we address this challenge: we propose a rootkit detection approach fo...

Teljes leírás

Elmentve itt :
Bibliográfiai részletek
Szerzők: Nagy Roland
Németh Krisztián
Papp Dorottya
Buttyán Levente
Testületi szerző: Conference of PhD Students in Computer Science (12.) (2020) (Szeged)
Dokumentumtípus: Cikk
Megjelent: University of Szeged, Institute of Informatics Szeged 2021
Sorozat:Acta cybernetica 25 No. 2
Kulcsszavak:Programozás, Számítástechnika
Tárgyszavak:
doi:10.14232/actacyb.288834

Online Access:http://acta.bibl.u-szeged.hu/75615
LEADER 02426nab a2200277 i 4500
001 acta75615
005 20220512152222.0
008 220512s2021 hu o 0|| eng d
022 |a 0324-721X 
024 7 |a 10.14232/actacyb.288834  |2 doi 
040 |a SZTE Egyetemi Kiadványok Repozitórium  |b hun 
041 |a eng 
100 1 |a Nagy Roland 
245 1 0 |a Rootkit detection on embedded IoT devices  |h [elektronikus dokumentum] /  |c  Nagy Roland 
260 |a University of Szeged, Institute of Informatics  |b Szeged  |c 2021 
300 |a 369-400 
490 0 |a Acta cybernetica  |v 25 No. 2 
520 3 |a IoT systems are subject to cyber attacks, including infecting embedded IoT devices with rootkits. Rootkits are malicious software that typically run with elevated privileges, which makes their detection challenging. In this paper, we address this challenge: we propose a rootkit detection approach for embedded IoT devices that takes advantage of a trusted execution environment (TEE), which is often supported on popular IoT platforms, such as ARM based embedded boards. The TEE provides an isolated environment for our rootkit detection algorithms, and prevents the rootkit from interfering with their execution even if the rootkit has root privileges on the untrusted part of the IoT device. Our rootkit detection algorithms identify modifications made by the rootkit to the code of the operating system kernel, to system programs, and to data influencing the control flow (e.g., hooking system calls), as well as inconsistencies created by the rootkit in certain kernel data structures (e.g., those responsible to handle process related information). We also propose algorithms to detect rootkit components in the persistent storage of the device. Besides describing our approach and algorithms in details, we also report on a prototype implementation and on the evaluation of our design and implementation, which is based on testing our prototype with rootkits that we developed for this purpose. 
650 4 |a Természettudományok 
650 4 |a Számítás- és információtudomány 
695 |a Programozás, Számítástechnika 
700 0 1 |a Németh Krisztián  |e aut 
700 0 1 |a Papp Dorottya  |e aut 
700 0 1 |a Buttyán Levente  |e aut 
710 |a Conference of PhD Students in Computer Science (12.) (2020) (Szeged) 
856 4 0 |u http://acta.bibl.u-szeged.hu/75615/1/cybernetica_025_numb_002_369-400.pdf  |z Dokumentum-elérés