首页> 外文会议>2011 International conference on network computing and information security >VMInsight: Hardware Virtualization-Based Process Security Monitoring System
【24h】

VMInsight: Hardware Virtualization-Based Process Security Monitoring System

机译:VMInsight:基于硬件虚拟化的过程安全监控系统

获取原文

摘要

Malicious software is one of the primary threats to information system on Internet, while the traditional host-based and network-based monitoring systems are vulnerable to prevent the malicious behavior of software because most current malicious software is capable of resisting security monitoring. Virtualization technology gives an impactful approach to monitoring the behavior of malicious software since it can provide an abstraction layer between the operating system and the hardware. In this paper, we propose a hardware-virtualization-based security monitor system named VMInsight, which can provide load-time and run-time monitoring for processes. VMInsight intercepts system calls and process behaviors by monitoring changes in the virtual machine CPU register, and it is implemented in the hyper visor, thus is completely transparent to the software and operating system running in the virtual machine. The experimental results show that the performance overhead of VMInsight is less than 10%, and it can be easily applied to the third-party security monitoring system.
机译:恶意软件是对Internet上信息系统的主要威胁之一,而传统的基于主机和基于网络的监视系统很容易阻止软件的恶意行为,因为当前大多数恶意软件都能够抵抗安全监视。虚拟化技术提供了一种有效的方法来监视恶意软件的行为,因为它可以在操作系统和硬件之间提供抽象层。在本文中,我们提出了一个名为VMInsight的基于硬件虚拟化的安全监视系统,该系统可以为流程提供加载时间和运行时监视。 VMInsight通过监视虚拟机CPU寄存器中的更改来拦截系统调用和进程行为,并且在管理程序中实现,因此对虚拟机中运行的软件和操作系统完全透明。实验结果表明,VMInsight的性能开销不到10%,可以轻松地应用于第三方安全监视系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号