首页> 外文会议>International Conference on Information Systems Security >A Universal Semantic Bridge for Virtual Machine Introspection
【24h】

A Universal Semantic Bridge for Virtual Machine Introspection

机译:用于虚拟机内省的通用语义桥

获取原文

摘要

All systems that utilize virtual machine introspection (VMI) need to overcome the disconnect between the low-level state that the hypervisor sees and its semantics within the guest. This problem has become well-known as the semantic gap. In this work, we introduce our tool, InSight, that establishes a semantic connection between the guest and the hypervisor independent of the application at hand. InSight goes above and beyond previous approaches in that it strives to expose all kernel objects to an application with as little human effort as possible. It features a shell interface for interactive inspection as well as a scripting engine for comfortable and safe development of new VMI-based methods. Due to this flexibility, InSight supports a wide variety of VMI applications, such as intrusion detection, forensic analysis, malware analysis, and kernel debugging.
机译:使用虚拟机内省(VMI)的所有系统都需要克服虚拟机管理程序所看到的低级状态和其语义之间的断开连接。这个问题变得众所周知的语义差距。在这项工作中,我们介绍了我们的工具,Insight,它在嘉宾和虚拟机管理程序之间建立了语义连接,而独立于手头的应用程序。洞察力远远超出以前的方法,因为它努力将所有内核对象暴露给应用程序尽可能少的人力努力。它具有用于交互式检查的Shell界面以及用于舒适安全的基于VMI的方法的脚本引擎。由于这种灵活性,Insight支持各种VMI应用程序,例如入侵检测,法医分析,恶意软件分析和内核调试。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号