Global Information Lookup Global Information

Hooksafe information


Hooksafe is a hypervisor-based lightweight system that protects an operating system's kernel hooks from rootkit attacks.[1]

It prevents thousands of kernel hooks in the guest operating system from being hijacked. This is achieved by making a shadow copy of all the kernel hooks at one central place and adding an indirection layer on it to regulate attempts to access the hooks. A prototype of Hooksafe was used on a Linux guest and protected nearly 6000 kernel hooks.[2][1] It focuses on protecting kernel control data that are function pointers. It provides large scale hook protection with small performance overhead[3]

  1. ^ a b "Countering Kernel Rootkits with Lightweight Hook Protection" (PDF). {{cite journal}}: Cite journal requires |journal= (help)
  2. ^ Jackson Higgins, Kelly (3 November 2009). "Researchers Create Hypervisor-Based Tool For Blocking Rootkits". Retrieved 1 July 2016.
  3. ^ "Boffins boast newfangled rootkit blocker". The Register.

and 3 Related for: Hooksafe information

Request time (Page generated in 0.8982 seconds.)

Hooksafe

Last Update:

Hooksafe is a hypervisor-based lightweight system that protects an operating system's kernel hooks from rootkit attacks. It prevents thousands of kernel...

Word Count : 185

Hypervisor

Last Update:

Carolina State University demonstrated a hypervisor-layer anti-rootkit called Hooksafe that can provide generic protection against kernel-mode rootkits. super-...

Word Count : 2766

Rootkit

Last Update:

Carolina State University demonstrated a hypervisor-layer anti-rootkit called Hooksafe, which provides generic protection against kernel-mode rootkits. Windows...

Word Count : 7087

PDF Search Engine © AllGlobal.net