Cross-Platform Memory Instrumentation Protection Technology and Efficient Micro-Patch Intervention Based on System Critical Calls
Main Article Content
Abstract
Continuous protection of cross-platform computing systems requires real-time monitoring, low-latency intervention, and adaptive security updates without service interruption. This study proposes a cross-platform memory instrumentation protection framework based on critical system-call semantics and an efficient micro-patch intervention mechanism. A unified runtime monitoring architecture is developed to provide platform-independent memory behavior acquisition through semantic abstraction and event-driven instrumentation. To enable dynamic protection evolution, a lightweight micro-patch engine is designed to support real-time address mapping, state-consistency verification, and atomic hot replacement of protection logic. A structured patch description model and collaborative interaction protocol are further established to ensure secure deployment and controllable activation across heterogeneous operating environments. Experimental evaluation on Linux and Windows platforms demonstrates that the proposed mechanism achieves atomic activation within 3.2–3.7 ms and completes dynamic intervention within 12.0–13.6 ms. The protection framework significantly improves attack interception capability while maintaining acceptable runtime overhead under varying system loads. By integrating runtime event monitoring, adaptive protection updating, and low-latency intervention mechanisms, the proposed approach provides an effective engineering solution for secure information processing, real-time system protection, and resilient distributed computing environments.
Downloads
Article Details

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).
References
Z. Xi, B. Zhang, A. Bhattacharjya, et al., “Research on a Secure and Reliable Runtime Patching Method for Cyber-Physical Systems and Internet of Things Devices,” Symmetry, vol. 17, no. 7, pp. 983-985, 2025, doi: 10.3390/sym17070983.
Y. Li, Y. Li, G. Wang, and H. Hu, “An Adaptive Dynamic Defense Strategy for Microservices Based on Deep Reinforcement Learning,” Electronics, vol. 14, no. 20, pp. 4096-4102, 2025, doi: 10.3390/electronics14204096.
C. Islam, V. Prokhorenko, and M. A. Babar, “Runtime software patching: Taxonomy, survey and future directions,” Journal of Systems and Software, vol. 200, no. 1, pp. 111652-111661, 2023, doi: 10.1016/j.jss.2023.111652.
M. Fruth and S. Scherzinger, “Live Patching for Distributed In-Memory Key-Value Stores,” Proceedings of the ACM on Management of Data, vol. 2, no. 6, pp. 1-26, 2024, doi: 10.1145/3698816.
H. Tu, L. Jiang, J. Hong, X. Ding, and H. Jiang, “Concretely mapped symbolic memory locations for memory error detection,” IEEE Transactions on Software Engineering, vol. 50, no. 7, pp. 1747-1767, 2024, doi: 10.1109/TSE.2024.3395412.
Y. Guo, Y. Zhang, and Y. Cao, “Detection Method for Closed-Source VxWorks Memory Protection Mechanisms Based on Dynamic Instruction Translation Monitoring,” Electronics, vol. 14, no. 22, pp. 4382-4387, 2025, doi: 10.3390/electronics14224382.
M. Altaibek, A. Issainova, T. Aidynov, D. Kuttymbek, G. Abisheva, and A. Nurusheva, “A Survey of Cross-Layer Security for Resource-Constrained IoT Devices,” Applied Sciences, vol. 15, no. 17, pp. 9691-9695, 2025, doi: 10.3390/app15179691.
X. Song and Z. Zhu, “Compatible Remediation for Vulnerabilities in the Presence and Absence of Security Patches,” Computers, Materials and Continua, vol. 86, no. 1, pp. 1-19, 2025, doi: 10.32604/cmc.2025.068930.
K. Wang, S. Wu, K. Suo, Y. Liu, H. Huang, Z. Huang, et al., “Characterizing and optimizing Kernel resource isolation for containers,” Future Generation Computer Systems, vol. 141, no. 1, pp. 218-229, 2023, doi: 10.1016/j.future.2022.11.018.
S. Yang, B. B. Kang, and J. Nam, “Optimus: association-based dynamic system call filtering for container attack surface reduction,” Journal of Cloud Computing, vol. 13, no. 1, pp. 71-72, 2024, doi: 10.1186/s13677-024-00639-3.
S. Park and Y. Park, “Detection Techniques for DBI Environment in Windows,” Electronics, vol. 13, no. 5, pp. 871-877, 2024, doi: 10.3390/electronics13050871.
W. Feng, S. Shang, P. Li, H. Yang, Z. Luan, and D. Qian, “SyncNOVA: an end-to-end fine-grained profiling tool oN lOck behaVior detection and critical section diAgnosis,” CCF Transactions on High Performance Computing, vol. 7, no. 1, pp. 100-113, 2025, doi: 10.1007/s42514-024-00210-1.
M. Kiperberg and N. J. Zaidenberg, “H-kpp: Hypervisor-assisted kernel patch protection,” Applied Sciences, vol. 12, no. 10, pp. 5076-5081, 2022, doi: 10.3390/app12105076.
C. Su, X. Xing, X. Cheng, R. Guo, and C. Luo, “LPAH: Illustrating Efficient Live Patching With Alignment Holes in Kernel Data,” IEEE Transactions on Computers, vol. 73, no. 10, pp. 2434-2448, 2024, doi: 10.1109/TC.2024.3424263.
G. Entrup, A. Kässens, B. Fiedler, and D. Lohmann, “Applied static analysis and specialization of cross-core syscalls for multi-core AUTOSAR OS,” Real-Time Systems, vol. 60, no. 3, pp. 491-533, 2024, doi: 10.1007/s11241-024-09429-1.
S. Tao, B. Zhang, and Q. Zhang, “ECHO: Enhancing Linux Kernel Fuzzing via Call Stack-Aware Crash Deduplication,” Electronics, vol. 14, no. 14, pp. 2914-2917, 2025, doi: 10.3390/electronics14142914.
M. Galarraga, C. A. Lefebvre, J. Perez-Cerrolaza, and J. A. Pascual, “Toward Linux-based safety-critical systems-Execution time variability analysis of Linux system calls,” Journal of Systems Architecture, vol. 156, no. 1, pp. 103266-103273, 2024, doi: 10.1016/j.sysarc.2024.103266.
T. Nguyen, M. Orenbach, and A. Atamli, “Live system call trace reconstruction on Linux,” Forensic Science International: Digital Investigation, vol. 42, no. 1, pp. 301398-3013102, 2022, doi: 10.1016/j.fsidi.2022.301398.
H. J. Hadi, M. Adnan, Y. Cao, F. B. Hussain, N. Ahmad, M. A. Alshara, et al., “ikern: Advanced intrusion detection and prevention at the kernel level using ebpf,” Technologies, vol. 12, no. 8, pp. 122-127, 2024, doi: 10.3390/technologies12080122.
M. Soltani Siapoush and J. Alves-Foss, “Zero-Copy Messaging: Low-Latency Inter-Task Communication in CHERI-Enabled RTOS,” Future Internet, vol. 17, no. 11, pp. 506-513, 2025, doi: 10.3390/fi17110506.
A. Rai and E. G. Im, “MemCatcher: An In-Depth Analysis Approach to Detect In-Memory Malware,” Applied Sciences, vol. 15, no. 21, pp. 11800-11809, 2025, doi: 10.3390/app152111800.
J. Shin, J. Kim, and J. Nam, “Aquila: Efficient In-Kernel System Call Telemetry for Cloud-Native Environments,” Sensors, vol. 25, no. 21, pp. 6511-6518, 2025, doi: 10.3390/s25216511.
Z. Chen, Q. Zhang, J. Wu, J. Yan, and J. Xue, “A source-level instrumentation framework for the dynamic analysis of memory safety,” IEEE Transactions on Software Engineering, vol. 49, no. 4, pp. 2107-2127, 2022, doi: 10.1109/TSE.2022.3210580.
Y. Park, S. Choi, U. Y. Choi, H. Jin, N. H. M. Nor, and Y. Park, “A practical approach for finding anti-debugging routines in the Arm-Linux using hardware tracing,” Scientific Reports, vol. 14, no. 1, pp. 14728-14734, 2024, doi: 10.1038/s41598-024-65374-w.
Z. Sha, C. Shepherd, A. Rafi, and Markantonakis, “Control-flow attestation: Concepts, solutions, and open challenges,” Computers & Security, vol. 150, no. 1, pp. 104254-104259, 2025, doi: 10.1016/j.cose.2024.104254.
H. Kuzuno and T. Yamauchi, “Mitigating Foreshadow Side-channel Attack Using Dedicated Kernel Memory Mechanism,” Journal of Information Processing, vol. 30, no. 1, pp. 796-806, 2022, doi: 10.2197/ipsjjip.30.796.
M. Huang and C. Song, “ARMPatch: A binary patching framework for ARM-based IoT devices,” Journal of Web Engineering, vol. 20, no. 6, pp. 1829-1852, 2021, doi: 10.13052/jwe1540-9589.2066.
H. Li, D. He, X. Zhu, and S. Chan, “P1ovd: Patch-based 1-day out-of-bounds vulnerabilities detection tool for downstream binaries,” Electronics, vol. 11, no. 2, pp. 260-263, 2022, doi: 10.3390/electronics11020260.
S. Woo, E. Choi, and H. Lee, “A large-scale analysis of the effectiveness of publicly reported security patches,” Computers & Security, vol. 148, no. 1, pp. 104181-104189, 2025, doi: 10.1016/j.cose.2024.104181.
H. Sharaf, I. Ahmad, and T. Dimitriou, “Extended berkeley packet filter: An application perspective,” IEEE Access, vol. 10, no. 1, pp. 126370-126393, 2022, doi: 10.1109/ACCESS.2022.3226269.
Z. Lu, Y. Tan, X. Cheng, Z. Zheng, N. Shi, and Y. Li, “An automated framework for detecting and mitigating memory safety vulnerabilities in UEFI firmware,” Computers and Electrical Engineering, vol. 122, no. 1, pp. 109945-109953, 2025, doi: 10.1016/j.compeleceng.2024.109945.
B. Tang, S. Zhang, F. Zhu, and A. Ye, “CAPRA: Context-Aware patch risk assessment for detecting immature vulnerability in open-source software,” Computers & Security, vol. 157, no. 1, pp. 104540-104544, 2025, doi: 10.1016/j.cose.2025.104540.
R. N. M. Watson, D. Chisnall, J. Clarke, B. Davis, N. W. Filardo, and B. Laurie, “Cheri: Hardware-enabled c/c++ memory protection at scale,” IEEE Security & Privacy, vol. 22, no. 4, pp. 50-61, 2024, doi: 10.1109/MSEC.2024.3396701.
L. Zhou, F. Zhang, K. Leach, X. Ding, Z. Ning, and G. Wang, “Hardware-Assisted Live Kernel Function Updating on Intel Platforms,” IEEE Transactions on Dependable and Secure Computing, vol. 21, no. 4, pp. 2085-2098, 2023, doi: 10.1109/TDSC.2023.3300101.
B. Novkovi´c and M. Golub, “Improving monolithic kernel security and robustness through intra-kernel sandboxing,” Computers & Security, vol. 127, no. 1, pp. 103104-103111, 2023, doi: 10.1016/j.cose.2023.103104.