
安全虚拟环境中的进程执行精确监控 被引量:5

Secure virtualization-based fine-grained process execution monitoring
摘要 提出了通过进程移植实现对用户级进程执行实施监控的方法,旨在同时解决隔离和兼容性问题,并采取重定向系统调用来保证被移植进程执行的连续性.实验结果表明了文中方法的有效性和可行性,以及对系统性能的微小影响. Computer malware has forced the transfer of the traditional in-host security tools to the development of VMM-based solutions which isolate the anti-malware software from untrusted systems.However,the inherent semantic gap poses a great challenge in supporting existing monitoring tools.In this paper,we present a process transferring method for fine-grained process execution monitoring to address both isolation and compatibility problems.Also by redirecting system calls invoked by the suspect process we guarantee the execution flow of the transferred process.Evaluation results show its effectiveness and feasibility with a tiny influence on the system.
出处 《西安电子科技大学学报》 EI CAS CSCD 北大核心 2012年第6期181-186,共6页 Journal of Xidian University
关键词 进程监控 语义鸿沟 虚拟机自省 process monitoring semantic gap virtual machine introspection
  • 相关文献


  • 1McAfee Threats Report. Fourth Quarter [R/OL]. [-2011-12-20]. http://www, mcafee, com/us/resources/reports/rp- quarterly-threat-q4-2010, pdf.
  • 2Azab A M, Ning P, Sezer E C, et al. HIMA: A Hypervisor-based Integrity Measurement Agent [C]//Proc of the 25th Annual Computer Security Applications Conference. Honolulu: IEEE, 2009: 461-470.
  • 3Garfinkel T, Rosenblum M. A Virtual Machine Introspection Based Architecture for Intrusion Detection[C]//Proc of Network and Distributed Systems Security Symposium. San Diego: ISOC, 2003: 191-206.
  • 4Payne B D, de Carbone M, Lee W K. Secure and Flexible Monitoring of Virtual Machines [C]//Proc of the 23re Annual Computer Security APplications Conference. Miami Beach: IEEE, 2007: 385-397.
  • 5Payne B D, de Carhone M, Sharif M, et al. Lares: An Architecture for Secure Active Monitoring Using Virtualization [C]//Proc of the 29th IEEE SympoSium on Security and Privacy. Oakland: IEEE, 2008: 233-247.
  • 6Dolan-Gavitt B, Leek T, Zhivich M, et al. Virtuoso: Narrowing the Semantic Gap in Virtual Machine Introspection [C]//Proc of the 32na IEEE Symposium on Security and Privacy. Berkeley: IEEE, 2011: 297-312.
  • 7Dolan-Gavitt B, Payne B D, Lee W K. Leveraging Forensic Tools for Virtual Machine Introspection [R]. Atlanta: Technical Report. Georgia Institute of Technology, GT-CS-11-05, 2011.
  • 8Klein G, Elphinstone K, Heiser G, et al. seL4 : Formal Verification of an OS Kernel [C]//Proc of the 22na Symposium on Operating Systems Principles. New York: ACM, 2009: 207-220.
  • 9Intel Corporation. Intel 64 and IA-32 Architectures Software Developer's Manual [M]. Raleigh: Intel Corporation, 2012 : Volume 3B.
  • 10Wikipedia. Kernel-based Virtual Machine [EB/OL]. [2012-01-10]. http://en, wikipedia, org/wiki/Kernel-based_Virtual Machine.


  • 1廖爱红,罗铭涛.埋点管理系统分析与设计[J].办公自动化,2020,25(16):33-35. 被引量:5
  • 2刘谦,王观海,翁楚良,骆源,李明禄.一种虚拟机系统下关于多级安全的强制访问控制框架Ⅱ:实现(英文)[J].China Communications,2011,8(2):86-94. 被引量:5
  • 3刘谦,王观海,翁楚良,等.一种虚拟机系统中关于多级安全的强制访问控制框架I:理论[J].中国通信,2010(4):137-143.
  • 4McKEOWN N, ANDERSON T, BALAKRISHNAN H, et al. Open- Flow: enabling innovation in campus networks [ J]. ACM SIG- COMM Computer Communication Review, 2008, 38(2) : 69 -74.
  • 5ELLIOTr C. GENI: opening up new classes of experiments in global networking [ J]. IEEE Intemet Computing, 2010, 14(1): 39 -42.
  • 6CHUN B, CULLER D, ROSCOE T, et al. PlanetLab: an overlay testbed for broad-coverage services [ J]. ACM SIGCOMM Computer Communication Review, 2003, 33(3) : 3 - 12.
  • 7GAVRAS A, KARILA A, FDIDA S, et al. Future Internet research and experimentation: the FIRE initiative [ J]. ACM SIGCOMM Computer Communication Review, 2007, 37(3) : 89 -92.
  • 8CoreLab Project. CoreLab home page [ EB/OL]. [ 2013-08-20]. http://www, corelab, ip/.
  • 9NAOUS J, ERICKSON D, COVINGTON G A, et al. Implemen- ting an OpenFlow switch on the NetFPGA platform [ C]//Proceed- ings of the 4th ACM/IEEE Symposium on Architectures for Networ- king and Communications Systems. New York: ACM, 2008:1 - 9.
  • 10OpenFlow Consortium. The OpenFlow switch specification [ EB! OL]. [ 2013- 08- 20]. http://archive, openflow, org/documents/openflow-spec-vl. 1. O. pdf.










使用帮助 返回顶部