Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering

Previous Articles     Next Articles

A Security Detection Framework Based on Virtual Machine Introspection

LIU Zheyuan,XU Jun,WANG Xing,GAO Hui   

  1. (The Third Research Institute of Ministry of Public Security,Shanghai 201204,China)
  • Received:2014-10-27 Online:2016-03-15 Published:2016-03-15

一种基于虚拟机自省的安全检测框架

刘哲元,徐隽,汪兴,高辉   

  1. (公安部第三研究所,上海 201204)
  • 作者简介:刘哲元(1982-),男,助理研究员、博士,主研方向为虚拟化安全技术、海量数据处理;徐隽(通讯作者),副研究员、硕士;汪兴、高辉,研究实习员、学士。

Abstract:

In order to detect and stop malicious stream that is disguised as legitimate application stream,a security framework based on virtual machine introspection technique is proposed.It uses hardware events combined with virtual machine introspection and memory analysis,authorizes outgoing application stream only if the data is truly based on user intent,and detects the behavior of malware software running application protocols or injecting legal procedure to prevent malicious data stream.The viability of this framework is demonstrated by implementing it along with support for email client application Outlook Express,proving its ability on security monitoring for PC to ensure the legitimacy of the network stream.

Key words: virtual machine introspection, user intent, network data stream, hardware event, memory analysis

摘要:

为检测并阻止伪装成合法应用程序数据流的恶意网络流量,提出一种基于虚拟机自省技术的安全框架,将硬件事件监控、虚拟机自省和内存分析相结合,依照用户真实意图对输出的应用程序数据流进行授权,以检测恶意软件正常运行应用程序协议或注入合法程序的行为,并阻止恶意数据流的发送。在邮件客户端Outlook Express上的实验结果验证了该框架的有效性,并通过性能评测表明其可用于个人计算机实施安全检测,以确保网络流量的合法性。

关键词: 虚拟机自省, 用户意图, 网络数据流, 硬件事件, 内存分析

CLC Number: