Netinfo Security ›› 2016, Vol. 16 ›› Issue (9): 134-138.doi: 10.3969/j.issn.1671-1122.2016.09.027

• Orginal Article • Previous Articles     Next Articles

The ELF File Integrity Checking Method Based on Granularity Extraction

Yongtang ZHANG1,2(), Jiawen CHOU1   

  1. 1. Department of Computer Science and Technology, Guangdong Neusoft Institute, Foshan Guangdong 528225, China
    2. Jiangxi Microsoft Technology Center, Nanchang Jiangxi 330003, China
  • Received:2016-07-25 Online:2016-09-20 Published:2020-05-13

Abstract:

This paper proposes a mobile trusted platform for ELF file integrity checking method (Random-MAC). And classifing the ELF file as the section of the key link and the section of different types and attribute classification, and according to a certain size, the contents of each section were selected and then proceed to checkout. In order to achieve high efficiency and high safety, the evaluation of different effect of particle size on the safety and efficiency of selection is made. In different versions of the Linux system, the collection of 2249 different formats of the ELF file and sizes of the sample is analysised by the integrity of the verification. The results show that RMAC can improve the calibration efficiency even more than twice the size of the appropriate extraction. While the RMAC one time check security performance in the acceptable range has declined. But because of its introduction, the random nature of the existing viruses can not be done every time through the RMAC check. So RMAC can prevent the outbreak of the virus.

Key words: trusted platform, mobile platform, executable file, integrity checking

CLC Number: