Browse > Article
http://dx.doi.org/10.3745/KIPSTC.2003.10C.6.675

Design and Implementation of Security Kernel Module with Additional Password for Enhancing Administrator Authentication  

Kim, Ik-Su (숭실대학교 대학원 컴퓨터공학과)
Kim, Myung-Ho (숭실대학교 컴퓨터학부)
Abstract
Attackers collect vulnerabilities of a target computer system to intrude into it. And using several attack methods, they acquire root privilege. They steal and alter information in the computer system, or destroy the computer sysem. So far many intrusion detection systems and firewallshave been developed, but recently attackers go round these systems and intrude into a computer system . In this paper, we propose security kernel module to prevent attackers having acquired root privilege from doing illegal behaviors. It enhances administrator authentication with additional password, so prevents attackers from doing illegal behaviors such as modification of important files and installation of rootkits. It sends warning mail about sttacker's illegal behaviors to administrators by real time. So using information in the mail, they can estabilish new security policies.
Keywords
System Security; Kernel Module; Intrusion Detection;
Citations & Related Records
연도 인용수 순위
  • Reference
1 이 호. 'Advanced Module Programming,' 2001
2 Pragmatic, 'Complete Linux Loadable Kernel Modules,' The hacker's choice, 1999
3 http://www.securitymap.net
4 http://packetstormsecurity.org
5 이현우, 김영직, 전숙, 'UNIX 피해시스템 분석 v1.1', 2002
6 Fyodor, 'The Art of Port Scanning,' Phrack Magazine, Vol.7, Issue 51, 1997
7 Aleph, 'Smashing The Stack For Fun And Profit,' Phrack Magazine, Vol.7, Issue 49, 1996
8 Andreas Thuemmel, 'Analysis of Format String Bugs,' 2001
9 이계찬, 이현우, 'Detecting Loadable Kernel Module Rootkit,' SecurityMap, 2002
10 정현철, 'IP Fragmentation을 이용한 공격기술들', 한국정보보호진흥원, 2001
11 Ori Pomerants, 'Linux Kernel Module Programming Guide,' 1999
12 한국정보보호진흥원, '12월 해킹바이러스 통계 및 분석 월보', 한국정보보호진흥원, 2002
13 http://www.cert.org/advisories/CA-2002-23.html