Linux内核
计算机科学
系统调用
操作系统
嵌入式系统
恶意软件
Linux统一密钥设置
工业互联网
计算机安全
物联网
作者
Ming Wan,Jiawei Li,Jiangyuan Yao
标识
DOI:10.1007/978-3-030-67537-0_25
摘要
With the deep integration of IT (Information Technology) and OT (Operational Technology), various Linux operating systems have been successfully applied in critical industrial devices, such as Linux-based IIoT (Industrial Internet of Things) controllers or gateways, and the vulnerabilities of these systems may become a new breakthrough for the organized and high-intensity attacks. In order to prevent malwares from corrupting or disabling industrial Linux-based devices, this paper proposes a novel real-time self-defense approach, which can be easily developed without redesigning the basic software and hardware platform. By establishing the customized Netlink connection between kernel mode and user mode, this approach can monitor all application processes, and block each new malicious application process, which cannot conform to the trusted white-listing rules. All experimental results show that the proposed approach has a comparative advantage to effectively detect and prevent the malware-related attacks, and provides a self-defense function for industrial Linux-based devices, which meets their availability due to the millisecond resolution.
科研通智能强力驱动
Strongly Powered by AbleSci AI