Monitoring user space processes using heartbeat messages authenticated based on integrity measurements
A technique includes receiving, by a monitoring agent, heartbeat messages that are associated with a status of a process of a computer system. The technique includes determining, by the monitoring agent and based on the heartbeat messages, whether the process has an expected state. The determination includes authenticating a given heartbeat message based on a content of the given heartbeat message and an expected integrity measurement of the process. The technique includes initiating, by the monitoring agent, a responsive action to counter tampering with the process responsive to the determination of whether the process has an expected state.
1 . A method comprising:
determining an expected integrity measurement of a process of a computer system, wherein determining the expected integrity measurement of the process comprises at least one of determining a hash of a content of a memory associated with the process or determining a hash of a content of an executable file associated with the process;
communicating, by a monitoring agent and with an operating system, to receive, by the monitoring agent, heartbeat messages associated with a status of the process;
determining, by the monitoring agent and based on the heartbeat messages, whether the process has an expected state, wherein determining whether the process has an expected state comprises authenticating a given heartbeat message of the heartbeat messages based on a content of the given heartbeat message and the expected integrity measurement of the process; and
initiating, by the monitoring agent, a responsive action to counter tampering with the process responsive to the determination of whether the process has an expected state.
2 . The method of claim 1 , wherein:
the content of the given heartbeat message comprises a first authentication code and a payload content; and
authenticating the given heartbeat message comprises:
determining, by the monitoring agent, a cryptographic key based on the expected integrity measurement;
determining, by the monitoring agent, a second authentication code based on the cryptographic key and the payload content; and
comparing, by the monitoring agent, the second authentication code to the first authentication code.
3 . The method of claim 2 , further comprising:
generating, by the monitoring agent, a nonce; and
sending, by the monitoring agent, the nonce, to an operating system agent that provides the heartbeat messages,
wherein determining the second authentication code further comprises:
generating, by the monitoring agent, an input for a keyed-hash function based on the payload content and the nonce; and
applying, by the monitoring agent, the keyed-hash function to the input based on the cryptographic key to provide the second authentication code.
4 . The method of claim 2 , further comprising:
sending, by the monitoring agent, a randomly-generated request identifier or a pseudorandomly-generated request identifier to an operating system agent that provides the heartbeat messages,
wherein determining the second authentication code further comprises:
generating, by the monitoring agent, an input for a keyed-hash function based on the payload content;
determining, by the monitoring agent, the cryptographic key based on a concatenation of the request identifier and the expected integrity measurement; and
applying, by the monitoring agent, a keyed-hash function to the input based on the cryptographic key to provide the second authentication code.
5 . The method of claim 1 , wherein determining whether the process has an expected state comprising evaluating, by the monitoring agent, a status of the process represented by the payload content.
6 . The method of claim 1 , further comprising:
responsive to a boot of the computer system, sending, by the monitoring agent, a registration request to an operating system agent of the computer system; and
receiving, by the monitoring agent and responsive to the registration request, a response message comprising payload content corresponding to the expected integrity measurement.
7 . The method of claim 6 , wherein the response message further comprises an authentication code, and sending the registration request comprises sending, by the monitoring agent and to the operating system agent, a message containing data representing a nonce and a request identifier, the method further comprising, responsive to receiving the response message:
authenticating, by the monitoring agent, the response message based on the payload content corresponding to the expected integrity measurement, the nonce, the request identifier and the authentication code.
8 . The method of claim 1 , further comprising sending, by the monitoring agent, a request for the given message.
9 . A non-transitory machine-readable storage medium that stores machine-readable instructions corresponding to an operating system kernel agent, wherein the machine-readable instructions, when executed by a hardware processor of a machine, cause the hardware processor to:
determine a hash of content corresponding to a user space process to measure the user space process to provide an integrity measurement of the user space process;
determine a status of the user space process; and
provide, to a monitoring agent, a report associated with the user space process, wherein providing the report comprises:
determining an authentication code based on the integrity measurement and the status of the user state process;
generating a message comprising data representing the status and the authentication code; and
sending the message to the monitoring agent.
10 . The non-transitory machine-readable storage medium of claim 9 , wherein the machine-readable instructions, when executed by the hardware processor, further cause the hardware processor to:
identify a text segment of a memory space corresponding to the user space process;
generate a hash of content corresponding to the text segment to provide the integrity measurement.
11 . The non-transitory machine-readable storage medium of claim 9 , wherein the machine-readable instructions, when executed by the hardware processor, further cause the hardware processor to:
identify a text segment of a user space corresponding to the user space process;
determine invariant content corresponding to a library dynamically linked to the user space process; and
generate a hash based on the content of the text segment and the invariant content to provide the integrity measurement.
12 . The non-transitory machine-readable storage medium of claim 9 , wherein the machine-readable instructions, when executed by the hardware processor, further cause the hardware processor to:
identify a text segment of a user space corresponding to the user space process;
access a first content of the text segment;
determine a runtime invariant content associated with the user space process other than the first content;
combine the first content and the runtime invariant content to provide an input;
apply the input to a hash function to provide the integrity measurement from which the authentication code is determined.
13 . The non-transitory machine-readable storage medium of claim 12 , wherein the runtime invariant content comprises data representing at least one of a process path corresponding to the user space process, a name of an executable file corresponding to the user space process, an argument passed to the user space process, or a version of the executable file.
14 . The non-transitory machine-readable storage medium of claim 9 , wherein the machine-readable instructions, when executed by the hardware processor, further cause the hardware processor to:
determine an input for a keyed-hash function based on a nonce provided by the monitoring agent; and
determine a cryptographic key for the keyed-hash function based on the integrity measurement and a request identifier provided by the monitoring agent,
wherein determining the authentication code comprises applying the keyed-hash function to the input using the cryptographic key to provide the authentication code.
15 . The non-transitory machine-readable storage medium of claim 9 , wherein the machine-readable instructions, when executed by the hardware processor, further cause the hardware processor to push the message to the monitoring agent.
16 . A computer system comprising:
a first computer platform comprising an execution environment, wherein the execution environment comprises:
a user space process; and
an operating system comprising a kernel agent to monitor a status of the user space process and generate a heartbeat message associated with the status of the user space process; and
a second computer platform comprising a processor-based controller external to the execution environment and comprising a hardware processor to:
receive the heartbeat message;
determine, based on the heartbeat message, whether the user space process has an expected state, wherein determining whether the user space process has an expected state comprises authenticating the heartbeat message based on a content of the heartbeat message and an expected integrity measurement of the user space process, wherein the expected integrity measurement comprises at least one of a hash of a content of a memory associated with the user space process or a hash of a content of an executable file associated with the user space process; and
initiate a responsive action to counter tampering with the user space process responsive to the determination of whether the user space process has an expected state.
17 . A computer system comprising:
a computer platform comprising:
an execution environment comprising:
a user space process; and
an operating system comprising a kernel agent to monitor a status of the user space process and generate a heartbeat message associated with the status of the user space process; and
a processor-based controller external to the execution environment and comprising a hardware processor to:
receive the heartbeat message;
determine, based on the heartbeat message, whether the user space process has an expected state, wherein determining whether the user space process has an expected state comprises authenticating the heartbeat message based on a content of the heartbeat message and an expected integrity measurement of the user space process, wherein the expected integrity measurement comprises at least one of a hash of a content of a memory associated with the user space process or a hash of a content of an executable file associated with the user space process; and
initiate a responsive action to counter tampering with the user space process responsive to the determination of whether the user space process has an expected state.
18 . The computer system of claim 17 , further comprising an interconnect, wherein the processor-based controller comprises a peripheral device to communicate with the kernel agent via the interconnect.