首页> 外文会议>International conference on ICT systems security and privacy protection >HyBIS: Advanced Introspection for Effective Windows Guest Protection
【24h】

HyBIS: Advanced Introspection for Effective Windows Guest Protection

机译:HYBIS:高级内省有效的Windows保护

获取原文

摘要

Effectively protecting the Windows? OS is a challenging task, since most implementation details are not publicly known. Windows OS has always been the main target of malware that have exploited numerous bugs and vulnerabilities exposed by its implementations. Recent trusted boot and additional integrity checks have rendered the Windows OS less vulnerable to kernel-level rootkits. Nevertheless, guest Windows Virtual Machines are becoming an increasingly interesting attack target. In this work we introduce and analyze a novel Hypervisor-Based Introspection System (HyBIS) we developed for protecting Windows OSes from malware and rootkits. The HyBIS architecture is motivated and detailed, while targeted experimental results show its effectiveness. Comparison with related work highlights main HyBIS advantages such as: effective semantic introspection, support for 64-bit architectures and for recent Windows versions (> win 7), and advanced malware disabling capabilities. We believe the research effort reported here will pave the way to further advances in the security of Windows~(TM) OSes.
机译:有效保护窗户?操作系统是一个具有挑战性的任务,因为大多数实现细节都不公开。 Windows操作系统始终是恶意软件的主要目标,它已利用其实现公开的许多错误和漏洞。最近受信任的启动和额外的完整性检查呈现了Windows操作系统,更容易受到内核级rootkits。尽管如此,客户窗口虚拟机正在成为越来越有趣的攻击目标。在这项工作中,我们介绍和分析我们开发的新型管理程序的内省系统(HYBIS),用于保护Windows对Mallware和Rootkits保护Windows OS。 Hybis架构是有动力和详细的,而目标实验结果表明其有效性。与相关工作的比较突出了主要的Hybis优势,例如:有效的语义内省,支持64位架构以及最近的Windows版本(> Win 7)和高级恶意软件禁用功能。我们认为,这里报告的研究努力将为Windows〜(TM)OS的安全性进一步进步。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号