This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
2011 IEEE 17th International Conference on Embedded and Real-Time Computing Systems and Applications
External Integrity Checking with Invariants
Toyama, Japan
August 28-August 31
ISBN: 978-0-7695-4502-8
In order to enhance OS security, most of people use security patches to fix the vulnerabilities of the OS. However, the security patches may also incur vulnerabilities. These vulnerabilities are generated since most OSes has a lot of functionalities and their functionalities are very complex to manage the entire source code manually. Moreover, in order to use the security patch, rebooting the system is required. Some of systems such as enterprise servers and embedded systems cannot accept the rebooting. Therefore, we propose an external integrity checking system to enhance the OS security. The external integrity checking system and a target OS run on a hyper visor simultaneously, therefore, their operations do not affect each other. In addition, the integrity checking system is generated automatically with invariants. Therefore, the possibility of inserting vulnerabilities into the system is as small as possible, and the system can cover a lot of vulnerabilities.
Index Terms:
invariant, monitoring service, security
Citation:
Hiromasa Shimada, Tatsuo Nakajima, "External Integrity Checking with Invariants," rtcsa, vol. 2, pp.122-125, 2011 IEEE 17th International Conference on Embedded and Real-Time Computing Systems and Applications, 2011
Usage of this product signifies your acceptance of the Terms of Use.