【24h】

Design of Virtualization Framework to Detect Cyber Threats in Linux Environment

机译:Linux环境下检测网络威胁的虚拟化框架设计

获取原文

摘要

In today's software and systems environments, security frameworks and models are evolving exponentially. Many traditional host-based frameworks are currently available to detect cyber threats in Linux environment. But there have been many challenges in detecting rootkits that modify the Linux Operating System (OS) kernel to avoid detection. These limitations have lead us to design a virtualization framework for detection of cyber threats in Linux environment. Instead of relying on the Linux Operating System kernel which is now a common victim of cyber-attacks, this virtualization framework will rely on the virtual machine hypervisor which is a more secure software layer that runs the OS kernel and the hardware. The paper proposed a virtualization framework based on well-known hypervisors, to detect cyber threats. The proposed work allowed for a more robust cyber threat detection method than traditional host-based frameworks. It can also possess self-healing properties since it will not only detect compromised servers but also suspend their operation by replacing them with uncompromised versions. This innovative framework promises to secure large scale IT infrastructure with minimum maintenance cost.
机译:在当今的软件和系统环境中,安全框架和模型正在呈指数级发展。当前,许多传统的基于主机的框架可用于检测Linux环境中的网络威胁。但是,在检测修改Linux操作系统(OS)内核以避免检测的rootkit时遇到了许多挑战。这些局限性促使我们设计了一个虚拟化框架,用于检测Linux环境中的网络威胁。该虚拟化框架不再依赖于现在是网络攻击的常见受害者的Linux操作系统内核,而是依赖于虚拟机管理程序,该虚拟机管理程序是运行OS内核和硬件的更安全的软件层。该白皮书提出了一种基于著名的虚拟机管理程序的虚拟化框架,以检测网络威胁。与传统的基于主机的框架相比,建议的工作提供了一种更强大的网络威胁检测方法。它也可以具有自我修复的特性,因为它不仅可以检测到受感染的服务器,还可以通过将它们替换为未损坏的版本来挂起它们的操作。这种创新的框架有望以最低的维护成本保护大规模的IT基础架构。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号