期刊文献+

基于虚拟机回放的恶意行为检测技术

Techniques for Detecting Malicious Behavior Based on Virtual Machine Replay
原文传递
导出
摘要 云计算环境下高灵活性、高扩展性、边界泛化等特性,使得已有的恶意行为检测技术误检率高,未知恶意行为检测能力低下.本文提出了基于虚拟机回放的恶意行为检测模型,该模型包括了基于行为关联图的警报关联算法和基于虚拟机回放的预警确认机制.首先在VMM层部署网络入侵检测和基于VMI的主机检测系统实现网络层和虚拟机内部的双层检测,然后警报关联结合双层检测结果进行综合评判发出预警,最后预警确认机制通过回放技术过滤虚假警报,并识别未知攻击.实验结果显示,回放开销相比ReVirt降低了21.8%,该方法相对于单一检测方法检测率有明显提升. Under the cloud computing environment,the high flexibility,high expansibility and boundary generalization characteristics have led to higher false detection rate of the malicious behavior detection technology and disability of the unknown malicious behavior detection.In this paper,we proposed a malicious behavior detection model based on virtual machine replay,which includes an alarm correlation algorithm and a pre-warning validation mechanism.First of all,we deployed both network intrusion detection system and VMI-based host detection system on VMM and acquired results respectively.Then,combining the double detection results,the alert correlation system would make a comprehensive evaluation and give pre-warning.In the end,with the help of virtual machine replay technique,the prewarning validation mechanism filtered false alerts and identified unknown attacks.Experimental results show that the replay overhead was 21.8%lower than that of ReVirt,which means the detection rate of this method has improved significantly compared with the single-detection method.
出处 《武汉大学学报(理学版)》 CAS CSCD 北大核心 2016年第5期437-443,共7页 Journal of Wuhan University:Natural Science Edition
基金 国家自然科学基金(61373169) 国家高技术研究发展(863)计划项目(2015AA016004) 信息保障技术重点实验室开放基金(KJ-14-110 KJ-14-101)
关键词 虚拟化安全 虚拟机回放 恶意行为检测 行为关联图 virtualization security virtual machine replay malicious behavior detection behavior association graph
  • 相关文献

参考文献1

二级参考文献4

共引文献62

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部