首页 | 本学科首页   官方微博 | 高级检索  
     

虚拟化环境下基于职能分离的Rootkit检测系统架构研究
引用本文:朱智强,赵志远,孙磊,杨杰.虚拟化环境下基于职能分离的Rootkit检测系统架构研究[J].计算机科学,2016,43(Z6):348-352.
作者姓名:朱智强  赵志远  孙磊  杨杰
作者单位:解放军信息工程大学三院 郑州450000,解放军信息工程大学三院 郑州450000,解放军信息工程大学三院 郑州450000,解放军信息工程大学三院 郑州450000
基金项目:本文受国家863计划基金项目(2008AA01Z404),国防预研基金项目(910A26010306JB5201)资助
摘    要:针对现有虚拟化环境下Rootkit检测技术易被绕过、性能开销大的问题,提出了虚拟化环境下基于职能分离的检测系统架构XenMatrix,其在保证检测系统透明性的同时提高了自身的安全性;设计了检测频率的自适应调整策略,实现了Rootkit检测频率的动态调整,有效降低了系统的性能开销。最后对实验结果的分析表明,相比现有检测技术,该原型系统能够有效检测Rookit,具有较高的检测率和较低的性能开销。

关 键 词:虚拟化  职能分离  Rootkit  自适应

Research on Rootkit Detection System Architecture Based on Functional Separation in Virtualized Environment
ZHU Zhi-qiang,ZHAO Zhi-yuan,SUN Lei and YANG Jie.Research on Rootkit Detection System Architecture Based on Functional Separation in Virtualized Environment[J].Computer Science,2016,43(Z6):348-352.
Authors:ZHU Zhi-qiang  ZHAO Zhi-yuan  SUN Lei and YANG Jie
Affiliation:The Third Institute,PLA Information Engineering University,Zhengzhou 450000,China,The Third Institute,PLA Information Engineering University,Zhengzhou 450000,China,The Third Institute,PLA Information Engineering University,Zhengzhou 450000,China and The Third Institute,PLA Information Engineering University,Zhengzhou 450000,China
Abstract:A kind of Rootkit detection system architecture XenMatrix based on duty separation in virtualization environment was proposed in light of the problems of Rootkit detection technology being easy to be avoided and large perfor-mance overhead in existing virtualization environment,which can improve the security of its own and at the same time ensure the transparency of the detecting system.A strategy of adaptive adjustment to detect the frequency was proposed,which can achieve dynamic adjustment of Rootkit detecting frequency and reduce the overhead of the system effectively.The analysis of experimental results shows that this prototype system can effectively detect known and unknown Rootkit and has higher success rate of detecting and lower performance overhead compared to existing detecting technology at present.
Keywords:Virtualization  Functional separation  Rootkit  Self-adaption
点击此处可从《计算机科学》浏览原始摘要信息
点击此处可从《计算机科学》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号