LKIM: The Linux Kernel Integrity Measurer

被引:0
作者
Pendergrass, J. Aaron
McGill, Kathleen N.
机构
来源
JOHNS HOPKINS APL TECHNICAL DIGEST | 2013年 / 32卷 / 02期
关键词
D O I
暂无
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The Linux Kernel Integrity Measurer (LKIM) is a next-generation technology for the detection of malicious modifications to a running piece of software. Unlike traditional antivirus systems, LKIM does not rely on a database of known malware signatures; instead, LKIM uses a precise model of expected program behavior to verify the consistency of critical data structures at runtime. APL and the Research Directorate of the National Security Agency (NSA) developed the LKIM prototype and are now working to transition the technology to a variety of critical government applications.
引用
收藏
页码:509 / 516
页数:8
相关论文
共 1 条
  • [1] Loscocco PA, 2007, STC'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON SCALABLE TRUSTED COMPUTING, P21