作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2009, Vol. 35 ›› Issue (8): 88-90. doi: 10.3969/j.issn.1000-3428.2009.08.030

• 软件技术与数据库 • 上一篇    下一篇

基于完全虚拟化的进程监控方法

杜 海,陈 榕   

  1. (复旦大学并行处理研究所,上海 201203)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2009-04-20 发布日期:2009-04-20

Full-virtualization-based Process Monitoring Method

DU Hai, CHEN Rong   

  1. (Institute of Parallel Processing, Fudan University, Shanghai 201203)
  • Received:1900-01-01 Revised:1900-01-01 Online:2009-04-20 Published:2009-04-20

摘要: 针对通用操作系统进程监控中存在的问题,提出一种基于完全虚拟化的进程监控方法,该方法利用完全虚拟化技术,在虚拟机监控器中对可疑进程产生的所有特权操作进行检测,并加以隔离。实验结果表明,该方法具有良好的透明性和可移植性,可以抵御多种攻击,且产生的性能损失较小。

关键词: 进程监控, 入侵检测, 虚拟化

Abstract: Aiming at the problems existed in Operating System(OS) process monitoring, a new full-virtualization-based process monitoring method is proposed. It uses full virtualization technology to detect and isolate all the harmful behaviors of untrusted processes in OS. Experimental results show this method has better performances of pellucidity and portability, which can prevent against multiple attacks and incur only a small amount of performance overhead.

Key words: process monitoring, intrusion detection, virtualization

中图分类号: