Section: New Software and Platforms
Conductor
Keywords: Intrusion Detection Systems (IDS) - Static analysis - Instrumentation
Functional Description: Conductor contains three main components: a static analysis to extract the expected behavior of the target, an instrumentation module to add instructions to the target's code in order to send messages to the co-processor, and an intrusion detection engine executed on the co-processor. The latter processes the messages sent by the instrumented target, describing its current behavior. This behavior is then compared against the expected behavior previously extracted by the static analysis.
-
Participants: Ronny Chevalier, Guillaume Hiet, Maugan Villatel and David Plaquin
-
Publication: Co-processor-based Behavior Monitoring: Application to the Detection of Attacks Against the System Management Mode