WEKO3
アイテム
SSdetector: Secure and Manageable Host-based IDS with SGX and SMM
http://hdl.handle.net/10228/0002000719
http://hdl.handle.net/10228/0002000719600a9983-c9e3-4d21-9d01-9bc97ddf854e
| 名前 / ファイル | ライセンス | アクション |
|---|---|---|
|
|
|
| アイテムタイプ | 学術雑誌論文 = Journal Article(1) | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 公開日 | 2024-06-04 | |||||||||||||
| 資源タイプ | ||||||||||||||
| 資源タイプ識別子 | http://purl.org/coar/resource_type/c_6501 | |||||||||||||
| 資源タイプ | journal article | |||||||||||||
| タイトル | ||||||||||||||
| タイトル | SSdetector: Secure and Manageable Host-based IDS with SGX and SMM | |||||||||||||
| 言語 | en | |||||||||||||
| 言語 | ||||||||||||||
| 言語 | eng | |||||||||||||
| 著者 |
Koga, Yoshimichi
× Koga, Yoshimichi
× 光来, 健一
WEKO
20772
|
|||||||||||||
| 抄録 | ||||||||||||||
| 内容記述タイプ | Abstract | |||||||||||||
| 内容記述 | Host-based intrusion detection systems (HIDS) are used to monitor the internals of target systems. It is essentially difficult to execute HIDS securely inside target systems. For example, it is not guaranteed that HIDS can obtain correct information from compromised systems. If HIDS is tampered with by intruders, it would be easily disabled. So far, various techniques have been proposed to securely execute HIDS using the security features of processors, e.g., System Management Mode (SMM) and SGX in Intel processors. However, strongly secure HIDS sacrifices its manageability, whereas manageable HIDS is less secure. In practice, it is important to achieve not only the security but also the manageability of HIDS. This paper proposes SSdetector for achieving both security and manageability by combining SGX and SMM. SSdetector securely runs HIDS inside an SGX enclave, which is a protected region inside an SGX application. Since HIDS is developed as an SGX application, the management of HIDS is easier. To securely obtain system information in memory, in-enclave HIDS invokes the SMM monitor running in an isolated execution environment created by BIOS. SSdetector protects information passed between in-enclave HIDS and the SMM monitor by encryption and integrity checking. We have implemented SSdetector in UEFI BIOS and examined the performance of HIDS collecting system information necessary for the proc filesystem. | |||||||||||||
| 言語 | en | |||||||||||||
| 備考 | ||||||||||||||
| 内容記述タイプ | Other | |||||||||||||
| 内容記述 | 2023 IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), 01-03 November, 2023, Exeter, United Kingdom | |||||||||||||
| 言語 | en | |||||||||||||
| 書誌情報 |
en : 2023 IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) p. 539-548, 発行日 2024-05-29 |
|||||||||||||
| 出版社 | ||||||||||||||
| 出版者 | IEEE | |||||||||||||
| DOI | ||||||||||||||
| 識別子タイプ | DOI | |||||||||||||
| 関連識別子 | https://doi.org/10.1109/TrustCom60117.2023.00086 | |||||||||||||
| ISBN | ||||||||||||||
| 識別子タイプ | ISBN | |||||||||||||
| 関連識別子 | 979-8-3503-8200-6 | |||||||||||||
| ISBN | ||||||||||||||
| 識別子タイプ | ISBN | |||||||||||||
| 関連識別子 | 979-8-3503-8199-3 | |||||||||||||
| ISSN | ||||||||||||||
| 収録物識別子タイプ | PISSN | |||||||||||||
| 収録物識別子 | 2324-898X | |||||||||||||
| ISSN | ||||||||||||||
| 収録物識別子タイプ | EISSN | |||||||||||||
| 収録物識別子 | 2324-9013 | |||||||||||||
| 著作権関連情報 | ||||||||||||||
| 権利情報 | Copyright (c) 2024 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works. | |||||||||||||
| キーワード | ||||||||||||||
| 主題Scheme | Other | |||||||||||||
| 主題 | Intel SGX | |||||||||||||
| キーワード | ||||||||||||||
| 主題Scheme | Other | |||||||||||||
| 主題 | system management mode | |||||||||||||
| キーワード | ||||||||||||||
| 主題Scheme | Other | |||||||||||||
| 主題 | hostbased IDS | |||||||||||||
| キーワード | ||||||||||||||
| 主題Scheme | Other | |||||||||||||
| 主題 | BIOS | |||||||||||||
| 出版タイプ | ||||||||||||||
| 出版タイプ | AM | |||||||||||||
| 出版タイプResource | http://purl.org/coar/version/c_ab4af688f83e57aa | |||||||||||||
| 査読の有無 | ||||||||||||||
| 値 | yes | |||||||||||||
| 研究者情報 | ||||||||||||||
| URL | https://hyokadb02.jimu.kyutech.ac.jp/html/303_ja.html | |||||||||||||
| 論文ID(連携) | ||||||||||||||
| 値 | 10429227 | |||||||||||||
| 連携ID | ||||||||||||||
| 値 | 11993 | |||||||||||||