首页 | 官方网站   微博 | 高级检索  
     

基于虚拟化的安全监控
引用本文:项国富,金海,邹德清,陈学广.基于虚拟化的安全监控[J].软件学报,2012,23(8):2173-2187.
作者姓名:项国富  金海  邹德清  陈学广
作者单位:1. 华中科技大学计算机科学与技术学院,湖北武汉,430074
2. 华中科技大学控制科学与工程系,湖北武汉,430074
基金项目:国家自然科学基金,国家高技术研究发展计划(863),武汉市科技攻关项目,信息网络安全公安部重点实验室开放课题
摘    要:近年来,虚拟化技术成为计算机系统结构的发展趋势,并为安全监控提供了一种解决思路.由于虚拟机管理器具有更高的权限和更小的可信计算基,利用虚拟机管理器在单独的虚拟机中部署安全工具能够对目标虚拟机进行检测.这种方法能够保证监控工具的有效性和防攻击性.从技术实现的角度来看,现有的研究工作可以分为内部监控和外部监控.根据不同的监控目的,详细地介绍了基于虚拟化安全监控的相关工作,例如入侵检测、蜜罐、文件完整性监控、恶意代码检测与分析、安全监控架构和安全监控通用性.最后总结了现有研究工作的不足,并指出了未来的研究方向.这对于从事虚拟化研究和安全监控研究都具有重要意义.

关 键 词:虚拟化  虚拟机管理器  安全监控  虚拟机自省
收稿时间:5/4/2011 12:00:00 AM
修稿时间:2011/11/2 0:00:00

Virtualization-Based Security Monitoring
XIANG Guo-Fu,JIN Hai,ZOU De-Qing and CHEN Xue-Guang.Virtualization-Based Security Monitoring[J].Journal of Software,2012,23(8):2173-2187.
Authors:XIANG Guo-Fu  JIN Hai  ZOU De-Qing and CHEN Xue-Guang
Affiliation:1(School of Computer Science and Technology,Huazhong University of Science and Technology,Wuhan 430074,China) 2(Department of Control Science and Engineering,Huazhong University of Science and Technology,Wuhan 430074,China)
Abstract:In recent years,virtualization technology is the novel trendy of computer architecture,and it provides a solution for security monitoring.Due to the highest privilege and the smaller trusted computing base of virtual machine monitor,security tools,deployed in an isolated virtual machine,can inspect the target virtual machine with the help of virtual machine monitor.This approach can enhance the effectiveness and anti-attack ability of security tools.From the aspect of the implementation technologies,existing research works can be classified into internal monitoring and external monitoring.According to the different targets,the related works about virtualization-based monitoring are introduced in this paper in detail,such as intrusion detection,honeypot,file integrity monitoring, malware detection and analysis,security monitoring architecture and the generality of monitoring.Finally,this paper summarizes the shortcomings of existing works,and presents the future research directions.It is significant for virtualization research and security monitoring research.
Keywords:virtualization  virtual machine monitor  security monitoring  virtual machine introspection
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《软件学报》浏览原始摘要信息
点击此处可从《软件学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号