首页> 外文会议>18th ACM conference on computer amp; communications security. >Process Out-Grafting: An Efficient 'Out-of-VM' Approach for Fine-Grained Process Execution Monitoring
【24h】

Process Out-Grafting: An Efficient 'Out-of-VM' Approach for Fine-Grained Process Execution Monitoring

机译:流程嫁接:一种有效的“虚拟机外”方法,用于细粒度的流程执行监控

获取原文
获取原文并翻译 | 示例

摘要

Recent rapid malware growth has exposed the limitations of traditional in-host malware-defense systems and motivated the development of secure virtualization-based out-of-VM solutions. By running vulnerable systems as virtual machines (VMs) and moving security software from inside the VMs to outside, the out-of-VM solutions securely isolate the anti-malware software from the vulnerable system. However, the presence of semantic gap also leads to the compatibility problem in not supporting existing defense software. In this paper, we present process out-grafting, an architectural approach to address both isolation and compatibility challenges in out-of-VM approaches for fine-grained process-level execution monitoring. Specifically, by relocating a suspect process from inside a VM to run side-by-side with the out-of-VM security tool, our technique effectively removes the semantic gap and supports existing user-mode process monitoring tools without any modification. Moreover, by forwarding the system calls back to the VM, we can smoothly continue the execution of the out-grafted process without weakening the isolation of the monitoring tool. We have developed a KVM-based prototype and used it to natively support a number of existing tools without any modification. The evaluation results including measurement with benchmark programs show it is effective and practical with a small performance overhead.
机译:最近恶意软件的快速增长暴露了传统的主机内恶意软件防御系统的局限性,并推动了基于安全虚拟化的VM外解决方案的开发。通过将易受攻击的系统作为虚拟机(VM)运行并将安全软件从VM内部移动到外部,VM外解决方案将反恶意软件软件与易受攻击的系统安全隔离。但是,语义间隙的存在还导致不支持现有防御软件的兼容性问题。在本文中,我们介绍了流程外移植,这是一种架构方法,可以解决用于精细粒度的流程级执行监控的VM外方法中的隔离和兼容性挑战。具体而言,通过从VM内部重新定位可疑进程以与VM外安全工具并排运行,我们的技术有效地消除了语义鸿沟,并且无需进行任何修改即可支持现有的用户模式进程监视工具。此外,通过将系统调用转发回VM,我们可以在不削弱监视工具的隔离性的情况下平稳地继续执行移植的过程。我们已经开发了一个基于KVM的原型,并使用它来原生支持许多现有工具,而无需进行任何修改。包括基准程序测量在内的评估结果表明,它是有效且实用的,而性能开销却很小。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号