A generic anti-spyware solution by access control list at kernel level

被引:8
作者
Chow, SSM [1 ]
Hui, LCK [1 ]
Yiu, SM [1 ]
Chow, KP [1 ]
Lui, RWC [1 ]
机构
[1] Univ Hong Kong, Dept Comp Sci & Informat Syst, Pokfulam, Hong Kong, Peoples R China
关键词
D O I
10.1016/j.jss.2004.05.027
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Spyware refers to programs that steal the user information stored in the user's computer and transmit this information via the Internet to a designated home server without the user being aware of this transmission. Existing anti-spyware solutions are not generic and flexible. These solutions either check for the existence of known spyware or try to block the transmission of the private information at the packet level. In this paper, we propose a more generic and flexible anti-spyware solution by utilizing an access control list in kernel mode of the operating system. The major difference between our approach and the existing approaches is that instead of asking a guard to look for the theft (spyware) or control the exit of the computer (and hence giving the spyware enough time to hide the information to be transmitted), we put a guard besides the treasure (the private information) and carefully control the access to it in the kernel mode. We also show the details of an implementation that realizes our proposed solution. (C) 2004 Elsevier Inc. All rights reserved.
引用
收藏
页码:227 / 234
页数:8
相关论文
共 9 条
[1]  
DIRK B, 2000, P 4 USENIX WIND SYST
[2]  
MCWILLIAMS B, 2002, NEWS ANT SPYW PROGR
[3]  
Mitnick K., 2002, The art of deception
[4]  
Oney W., 1999, PROGRAMMING MICROSOF
[5]  
OTT A, 2001, P 8 INT LIN K 2001
[6]  
Ott A., 1998, P 3 NORD WORKSH SEC
[7]  
SKORMIN VA, 2003, LECT NOTES COMPUTER, V2776
[8]  
WAHBE R, 1993, P S OP SYST PRINC
[9]  
[No title captured]