Real-Time Self-defense Approach Based on Customized Netlink Connection for Industrial Linux-Based Devices

Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications EngineeringCollaborative Computing: Networking, Applications and Worksharing(2021)

引用 0|浏览1
暂无评分
摘要
With the deep integration of IT (Information Technology) and OT (Operational Technology), various Linux operating systems have been successfully applied in critical industrial devices, such as Linux-based IIoT (Industrial Internet of Things) controllers or gateways, and the vulnerabilities of these systems may become a new breakthrough for the organized and high-intensity attacks. In order to prevent malwares from corrupting or disabling industrial Linux-based devices, this paper proposes a novel real-time self-defense approach, which can be easily developed without redesigning the basic software and hardware platform. By establishing the customized Netlink connection between kernel mode and user mode, this approach can monitor all application processes, and block each new malicious application process, which cannot conform to the trusted white-listing rules. All experimental results show that the proposed approach has a comparative advantage to effectively detect and prevent the malware-related attacks, and provides a self-defense function for industrial Linux-based devices, which meets their availability due to the millisecond resolution.
更多
查看译文
关键词
Self-defense, Customized Netlink, Application process, Industrial Linux-based devices
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要