【24h】

hGuard: A Framework to Measure Hypervisor Critical Files

机译:hGuard:一种衡量系统管理程序关键文件的框架

获取原文
获取原文并翻译 | 示例

摘要

Virtualization has been widely adopted in current computer systems. A key part of virtualization is a hyper visor, which virtualizes physical resources to be shared among multiple guest virtual machines (VMs). Configuration files and security policy files used by the hyper visor control VMs' behavior. If these critical files are tampered with, all the VMs that run on the same hyper visor will be affected. This paper presents hGuard, a framework to measure hyper visor critical files. Each time a critical file is updated, its hash is stored into a non-volatile storage of the trusted chip. When a critical file is loaded into memory, a measurement module computes its hash and a validation module checks its integrity by comparing this hash with that stored in the non-volatile storage. Only if they are the same could the files be used and continuous operation will be allowed. The experiment shows that hGuard can detect illegal modification of hyper visor critical files.
机译:虚拟化已被当前计算机系统广泛采用。虚拟化的关键部分是管理程序,它可以虚拟化要在多个来宾虚拟机(VM)之间共享的物理资源。管理程序使用的配置文件和安全策略文件控制VM的行为。如果篡改了这些关键文件,则将影响在同一虚拟机监控程序上运行的所有VM。本文介绍了hGuard,它是衡量虚拟机监控程序关键文件的框架。每次更新关键文件时,其哈希都会存储到受信任芯片的非易失性存储中。当关键文件加载到内存中时,测量模块将计算其哈希值,而验证模块则通过将该哈希值与非易失性存储器中存储的哈希值进行比较来检查其完整性。仅当它们相同时,才可以使用文件并允许连续操作。实验表明,hGuard可以检测到对管理程序关键文件的非法修改。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号