首页> 外文会议>AASRI International Conference on Engineering and Technology >Design of a Hypervisor-based Rootkit Detection Method for Virtualized Systems in Cloud Computing Environments
【24h】

Design of a Hypervisor-based Rootkit Detection Method for Virtualized Systems in Cloud Computing Environments

机译:云计算环境中虚拟化系统的虚拟机制rootkit检测方法设计

获取原文

摘要

Cloud computing is becoming increasingly popular. Many companies utilize cloud computing services to minimize IT infrastructure costs. The popularity of cloud computing has attracted the interest of cyber criminals. As the result, virtualized environments are a valid and attractive target for APT attacks. Since the key components in APT attacks are rootkit malware that provides stealth, detecting rootkits is an effective measure for protecting against APT attacks. Traditional rootkit detection algorithms are based on non-virtualized environments, where a detection agent tries to identify incoherency in OS system calls to detect rootkits. However, applying these algorithms to cloud computing environments entails installing a copy of the detection agent in every virtual machine, resulting in inefficient storage use and performance degradation. We propose a hypervisor-based, out-of-the-box rootkit detection system that takes cloud computing environments into consideration. The method utilizes vIPS platform to gain many beneficial traits including hypervisor-independency, agentless virtual security appliance structure, and usability. Therefore the method provides effective protection against rootkits in cloud computing environments.
机译:云计算变得越来越受欢迎。许多公司利用云计算服务来最大限度地减少IT基础架构成本。云计算的普及吸引了网络犯罪分子的兴趣。结果,虚拟化环境是APT攻击的有效和有吸引力的目标。由于APT攻击中的关键组件是提供隐身的rootkit恶意软件,因此检测rootkits是一种有效的保护,用于保护APT攻击。传统的rootkit检测算法基于非虚拟化环境,其中检测代理试图识别OS系统调用中的不一致以检测rootkits。但是,将这些算法应用于云计算环境需要在每个虚拟机中安装检测代理的副本,从而导致效率低下的存储使用和性能下降。我们提出了一个基于虚拟机制的外root rootkit检测系统,它考虑了云计算环境。该方法利用VIPS平台获得许多有益特征,包括虚拟机制独立性,无代理虚拟安全设备结构和可用性。因此,该方法为云计算环境中的rootkit提供了有效的保护。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号