Dissertation > Excellent graduate degree dissertation topics show
Research on Key Technologies for Detection and Exploitation of Windows Kernel Vulnerabilities
Author: NiTao
Tutor: WangQingXian
School: PLA Information Engineering University
Course: Applied Computer Technology
Keywords: Windows Kernel Drivers DeviceloControl Mechanism Fuzzing Testing TaintAnalysis Vulnerability Exploitation
CLC: TP393.08
Type: Master's thesis
Year: 2013
Downloads: 2
Quote: 0
Read: Download Dissertation
Abstract
|
The DeviceIoControl mechanism is the key communication mechanism of user mode and kernel mode in Windows system. In this thesis, Kernel driver vulnerabilities of this mechanism is focused, including the detection and the exploitation of these vulnerabilities. To detect the DeviceIoControl vulnerabilities, fuzzing testing is the main technology in recent public researches, which is a black-box testing in essence and lack of the dynamic information of kernel drivers, leading to a blindness in testing. Besides, the analysis and summary of vulnerability pattern is insufficient. The exploitation of kernel vulnerabilities is different from the user mode, as the particularity of kernel mode. With the appearance of the latest exploitation mitigation technology, higher challenge is proposed in the research of exploitation techonology. In this thesis, these problems is researched, the major contents include:1. Analyse the public kernel DeviceIoControl vulnerabilities, sum the WTVTA (Write Tainted Value to Tainted Address) vulnerability pattern up, introduce the traditional static taint analysis technology into kernel drivers, define the tainted input and the propagation path in kernel drivers, propose a new static detection algorithm based on WTVTA pattern. By detecting the MS11-062vulnerability, validate the effectiveness of the new algorithm.2. Design and realize a new testing frame for kernel drivers, propose a new heuristic static algorithm to search all testing interfaces. The testing program is deployed in a virtual machine, thus the monitoring is achieved via communication between the console and the testing program. During the testing, dynamic information of kernel drivers is collected and guide the generation of the following testing cases. Kernel drivers of4famous antivirus software is chosen to apply a real testing and the result proves that the coverage of testing interfaces, the effectiveness of testing cases and the efficiency are better than traditional testing technologies. Four undiscovered vulnerabilities are found in this testing.3. Sum the exploitation technologies of WTVTA vulnerability up, including the hijacking of control flow and the construction of kernel shellcode. Besides the latest exploitation mitigation technologies are researched to find out how they truncate the traditional exploitation path. At last, new exploitation technologies are proposed against the mitigation to achieve a privilege escalation.
|
Related Dissertations
- Research and Implement of SIP Vulnerability Exploitation in IMS,TN915.08
- The Research of Malware Detection Technology Based on Active Mode,TP393.08
- Research of IRC Botnet Detection Based on Behavior,TP393.08
- Research on the Impact Analysis of Network Security Incidents Based on Simulation,TP393.08
- Topology Measurement and Security Analysis on Gnutella and eMule Network,TP393.08
- Implementation and Research of Illegal Websites Detection System Based on Comparison Methods,TP393.08
- Analysis and research -based HTTP proxy security gateway,TP393.08
- Association rule mining based Intrusion Detection System Research and Implementation,TP393.08
- Encryption Card Application of Embedded Hardware Firewall Based on IPsec VPN,TP393.08
- Research on Intrusion Detection Based on Feature Selection,TP393.08
- Research and Implementation of Application Traffic Classification & Restoring,TP393.08
- E-Government Network Security Analysis and Prevention Strategy,TP393.08
- The Research on Intrusion Detection System Based on Machine Learning,TP393.08
- Design of Network Intrusion Detection System Based on FPGA,TP393.08
- Research of Key Technologies of Intrusion Detection Based on Computer Immune,TP393.08
- One based on pattern matching lightweight network intrusion detection system design and implementation,TP393.08
- Chain Enterprise Information Management System Design and Implementation of encryption technology,TP393.08
- Analysis on DDoS Attacks Detecting Technology Based on Eigenvector,TP393.08
- Internet IP-level topology measurement space research,TP393.08
- Research of Security Application in Enterprise Based on PKI Technology,TP393.08
- Research on Intrusion Prevention Based on Semi-Supervised Fuzzy Clustering,TP393.08
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|