摘要
基于访问控制策略,对Linux系统可加载内核模块LKM机制的安全缺陷进行了研究,对各种利用LKM的攻击方法进行了深入的综合分析,最后从监控所有的模块操作、基于capabilities能力机制的权限分解、基于加密模块的安全的LKM这3个方面,对LKM安全增强技术进行了探讨,并重点从机密模块加载过程、ELF格式文件操作等关键技术,对基于加密模块的安全LKM设计进行阐述。
The security flaw of Linux loadable kernel modules is analyzed based on its access control strategy. Then the attack methods based on LKM are integrated analyzed. At last, the security-enhanced technologies are discussed, which include monitoring all the operations relative to modules, privileges divided using capabilities facility and security LKM based on encrypted modules. The design of security LKM based on encrypted modules is discussed, which includes key technologies such as the load of encrypted modules and operate of ELF files.
出处
《计算机工程与设计》
CSCD
北大核心
2007年第20期4904-4907,共4页
Computer Engineering and Design