๐Ÿ‡Init Analyzer

Windows Kernel Driver ์ทจ์•ฝ์ ์„ ์•…์šฉํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” Medium Integrity์ดํ•˜ ๊ถŒํ•œ์—์„œ Driver์— ๊ฐ’์„ ์ „๋‹ฌํ•  ์ˆ˜ ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ƒ์šฉ ํ”„๋กœ๊ทธ๋žจ์—์„œ ์‚ฌ์šฉ๋˜๋Š” ๋“œ๋ผ์ด๋ฒ„ 100๊ฐœ ์ด์ƒ์„ ๋ถ„์„ํ•ด๋ณธ ๊ฒฐ๊ณผ, High Integrity์ด์ƒ์˜ ๊ถŒํ•œ์—์„œ ๋“œ๋ผ์ด๋ฒ„์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋Š” ์‚ฌ๋ก€๋„ ์กด์žฌํ–ˆ์Šต๋‹ˆ๋‹ค.

์ €ํฌ๋Š” ์ƒ์šฉ ํ”„๋กœ๊ทธ๋žจ์„ (1) ์–ด๋–ค Kernel Driver๋ฅผ ์„ค์น˜ํ•˜์—ฌ ์‚ฌ์šฉํ•˜๋Š”์ง€, (2) Attack Surface๋กœ์„œ ํ™œ์šฉ ๊ฐ€๋Šฅ์„ฑ(Medium ๊ถŒํ•œ์—์„œ Handle์ด ์ ‘๊ทผ ๊ฐ€๋Šฅํ•œ์ง€)์„ ํ™•์ธํ•˜๋Š” ๊ณผ์ •์„ ์ž๋™ํ™”ํ•˜์—ฌ ๋น ๋ฅธ ์‹œ๊ฐ„ ๋‚ด ํŒŒ์•…ํ•˜๊ณ ์ž ํ•˜์˜€์Šต๋‹ˆ๋‹ค.

๊ตฌ์ฒด์ ์ธ ๊ณผ์ •์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

  1. Installation์„ ์ˆ˜์ง‘

  2. ์„ค์น˜ ์ „๊ณผ ํ›„ VM์˜ Filesystem๊ณผ Service ์ƒํƒœ๋ฅผSnapshotํ•˜์—ฌ diff๋ฅผ ์ˆ˜ํ–‰

  3. ์ƒˆ๋กœ ์ƒ์„ฑ ๋ฐ ๋กœ๋“œ๋œ Driver๋ฅผ ํ™•์ธ

  4. Driver์—์„œ Symbol Name์„ ํŒŒ์‹ฑ

  5. User ๊ถŒํ•œ(Medium Integrity)์œผ๋กœ Handle์„ ํš๋“ํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ํ™•์ธ

Last updated