首页 | 本学科首页   官方微博 | 高级检索  
     

基于硬件架构和虚拟化扩展机制的虚拟机自省机制研究
引用本文:邹冰玉,张焕国,陈景君.基于硬件架构和虚拟化扩展机制的虚拟机自省机制研究[J].四川大学学报(工程科学版),2015,47(1):54-59.
作者姓名:邹冰玉  张焕国  陈景君
作者单位:武汉大学计算机学院,武汉大学计算机学院,湖北源辉科技有限公司
基金项目:基金项目1针对量子计算机特点的公钥密码理论与关键技术研究(基金编号:61332019);基金项目2云计算安全基础理论与方法研究(基金编号:2014CB340600)
摘    要:针对现有虚拟机自省技术利用不可信被监控操作系统的内核数据结构在内存中的期望布局及内核函数构建被监控系统语义、无法抵抗直接内核数据结构操纵攻击的问题,对虚拟机自省机制的能力进行全面分析,并对利用虚拟机自省机制可应对的恶意攻击进行分类,提出更具健壮性的基于硬件体系架构和虚拟化扩展机制的虚拟机自省技术,通过硬件体系结构提供的虚拟机自省特性被动地观察与收集被监控系统信息,并利用虚拟硬件扩展机制主动地截获客户虚拟机内部的事件和指令,达到主动监控的目的.描述了基于硬件的虚拟机自省机制在系统调用序列收集与监控上的应用,并进行了效率测试分析.

关 键 词:虚拟机  自省  虚拟化扩展
收稿时间:2014/6/25 0:00:00
修稿时间:2014/11/17 0:00:00

Study of Virtual Machine Introspection Based on Hardware Architecture and Virtualization Extensions
Zou Bingyu,Zhang Huanguo and Chen Jingjun.Study of Virtual Machine Introspection Based on Hardware Architecture and Virtualization Extensions[J].Journal of Sichuan University (Engineering Science Edition),2015,47(1):54-59.
Authors:Zou Bingyu  Zhang Huanguo and Chen Jingjun
Affiliation:School of Computer,Wuhan Univ.;Key Lab. of Aerospace Info. Security and Trusted Computing of Ministry of Education,Wuhan Univ.;School of Computer,Wuhan Univ.;Key Lab. of Aerospace Info. Security and Trusted Computing of Ministry of Education,Wuhan Univ.;Yuanhui Technol Co.
Abstract:Recent studies on virtual machine introspection mostly build guest VM state by the use of guest OS kernel data structures and kernel functions, which can be maliciously subverted. They are unable to resist direct kernel structure attacks. In view of the above situation, the capability of VMI was analyzed thoroughly, and then the possibilities of using hardware architectural knowledge and virtualization extension knowledge to construct VMI technology were explored and the possible attacks that can be detected and foiled by this mechanism were discussed. Collection and monitoring of system calls using the proposed method were described and the efficient of the monitored system was analyzed.
Keywords:virtualization  virtual machine introspection  virtualization extension
本文献已被 万方数据 等数据库收录!
点击此处可从《四川大学学报(工程科学版)》浏览原始摘要信息
点击此处可从《四川大学学报(工程科学版)》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号