The detector reveals stealthy peripheral-based attacks on the host’s main memory by exploiting certain hardware properties, while a permanent and resource-efficient measurement strategy ensures that the detector is also capable of detecting transient attacks, which can otherwise succeed when the applied strategy only measures intermittently.
Introduction.- Technical Background, Preliminaries and Assumptions.- Related Work.- Study of a Stealthy, Direct Memory Access based Malicious Software.- A Primitive for Detecting DMA Malware.- Authentic Reporting to External Platforms.- Conclusions and Future Work.