Isolate and Detect the Untrusted Driver with a Virtual Box
YongGang Li, ShunRong Jiang, Yu Bao, Pengpeng Chen, Yong Zhou, Yeh-Ching Chung
Abstract
In kernel, the driver code is much more than the core code, thus having a larger attack surface. Especially for the untrusted drivers without source code, they may come from the hot-plug hardware or the user without security knowledge. Traditional isolation methods require analyzing source code to set checkpoints in the driver for control flow protection, which are not available for closed-source drivers. Evenworse, the existing isolation methods can only prevent the hijacked control flows entering/existing drivers, while they cannot discover the illegal control flows inside drivers. Although the kernel address space location randomization (KASLR) can defend against control flow hijacking, it can be bypassed by code probes. In response to these issues, this paper proposes a novel method Dbox to isolate and detect the untrusted drivers whose source code is unavailable. Dbox creates a light hypervisor to monitor and analyze the untrusted driver's behavior without relying on source code. It isolates the untrusted driver in a private space and dynamically changes its virtual space through a sliding space mechanism. Under the protection of Dbox, all control flows jumping to/from untrusted drivers can be detected. Experiments and analysis show that Dbox has good protection against code probes, kernel rootkits and code reuse attacks, and the overhead introduced to the operating system is less than 3.6% in general scenarios.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get cd6c044c-ad7d-4040-a65c-d23e48f7a7a8Related papers
- DriverJar: Lightweight Device Driver Isolation for ARMHuamao Wu, Yuan Chen, Yajin Zhou, Yifei Wang et al.DAC 2023 · 3 citations
- Breaking Kernel Address Space Layout Randomization with Intel TSXYeongjin Jang, Sangho Lee, Taesoo KimCCS 2016 · 174 citations
- Unveiling BYOVD Threats: Malware's Use and Abuse of Kernel DriversAndrea Monzani, Antonio Parata, Andrea Oliveri, Simone Aonzo et al.NDSS 2026 · 5 citations
- BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating SystemsAlexander Van't Hof, Jason NiehOSDI 2022 · 44 citations
- Adelie: continuous address space layout re-randomization for Linux driversRuslan Nikolaev, Hassan Nadeem, Cathlyn Stone, Binoy RavindranASPLOS 2022 · 20 citations
