USENIX Security2018Top-tier venue
Fast and Service-preserving Recovery from Malware Infections Using CRIU
Ashton Webster, Ryan Eckenrod, James Purtilo
Abstract
Once a computer system has been infected with malware, restoring it to an uninfected state often requires costly service-interrupting actions such as rolling back to a stable snapshot or reimaging the system entirely. We present CRIU-MR: a technique for restoring an infected server system running within a Linux container to an uninfected state in a service-preserving manner using Checkpoint/Restore in Userspace (CRIU). We modify the CRIU source code to flexibly integrate with existing malware detection technologies so that it can remove suspected malware processes within a Linux container during a checkpoint/restore event. This allows for infected containers with a potentially damaged filesystem to be checkpointed and subsequently restored on a fresh backup filesystem while both removing malware processes and preserving the state of trusted ones. This method can be quickly performed with minimal impact on service availability, restoring active TCP connections and completely removing several types of malware from infected Linux containers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a358c646-0713-4c27-b21c-019c5f4a36e2Cited by top-tier papers1
Ask how each one uses itBuilds on3
- Optimized Invariant Representation of Network Traffic for Detecting Unseen Malware VariantsKarel Bartos, Michal Sofka, Vojtech FrancUSENIX Security 2016 · 147 citations
- A Lustrum of Malware Network Communication: Evolution and InsightsChaz Lever, Platon Kotzias, Davide Balzarotti, Juan Caballero et al.S&P 2017 · 86 citations
- UNVEIL: A Large-Scale, Automated Approach to Detecting RansomwareAmin Kharraz, Sajjad Arshad, Collin Mulliner, William K. Robertson et al.USENIX Security 2016
Related papers
- Using Trātṛ to tame Adversarial SynchronizationYuvraj Patel, Chenhao Ye, Akshat Sinha, Abigail Matthews et al.USENIX Security 2022
- CLARION: Sound and Clear Provenance Tracking for Microservice DeploymentsXutong Chen, Hassaan Irshad, Yan Chen, Ashish Gehani et al.USENIX Security 2021 · 38 citations
- Cross Container Attacks: The Bewildered eBPF on CloudsYi He, Roland Guo, Yunlong Xing, Xijia Che et al.USENIX Security 2023
- BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating SystemsAlexander Van't Hof, Jason NiehOSDI 2022 · 44 citations
- LightRIM: Light Runtime Integrity Measurement for Linux Kernels in Embedded ApplicationsYili Guo, Zhuoran Ma, Xiangyue Li, Jiajia Huang et al.DAC 2025
