首页> 外文会议>Information systems security >A Universal Semantic Bridge for Virtual Machine Introspection
【24h】

A Universal Semantic Bridge for Virtual Machine Introspection

机译:虚拟机自检的通用语义网桥

获取原文
获取原文并翻译 | 示例

摘要

All systems that utilize virtual machine introspection (VMI) need to overcome the disconnect between the low-level state that the hypervisor sees and its semantics within the guest. This problem has become well-known as the semantic yap. In this work, we introduce our tool, InSight, that establishes a semantic connection between the guest and the hypervisor independent of the application at hand. InSight goes above and beyond previous approaches in that it strives to expose all kernel objects to an application with as little human effort as possible. It features a shell interface for interactive inspection as well as a scripting engine for comfortable and safe development of new VMI-based methods. Due to this flexibility, InSight supports a wide variety of VMI applica tions, such as intrusion detection, forensic analysis, malware analysis, and kernel debugging.
机译:所有利用虚拟机自检(VMI)的系统都需要克服虚拟机管理程序看到的低级状态与其来宾内部语义之间的脱节。这个问题已成为众所周知的语义错误。在这项工作中,我们介绍了我们的工具InSight,该工具在访客和管理程序之间建立了语义连接,而与当前的应用程序无关。 InSight超越了先前的方法,它致力于以尽可能少的人力将所有内核对象公开给应用程序。它具有用于交互式检查的外壳界面以及用于舒适,安全地开发基于VMI的新方法的脚本引擎。由于这种灵活性,InSight支持各种VMI应用程序,例如入侵检测,取证分析,恶意软件分析和内核调试。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号