IVirt: Runtime environment integrity measurement mechanism based on virtual machine introspection

被引:0
|
作者
School of Computer Science, Beijing University of Posts and Telecommunications, Beijing [1 ]
100876, China
不详 [2 ]
100876, China
不详 [3 ]
100876, China
机构
来源
Jisuanji Xuebao | / 1卷 / 191-203期
关键词
D O I
10.3724/SP.J.1016.2015.00191
中图分类号
学科分类号
摘要
Integrity Measurement is an important method to detect compromised application, but under the virtualization environment traditional detection approaches have reflected some shortages. For example, the measurement software and measured objects are in the same operating system, so the measurement software is easily attacked. From the perspectives of security and performance, this paper proposes an integrity measurement mechanism based on virtual machine introspection-IVirt (Integrity for Virtualization). This mechanism obtains the needed memory data of virtual machine through address translation and content locating from outside of that virtual machine, thereby measuring the integrity of applications that are in the virtual machine is performed, so as to verify whether the applications are tampered with. The IVirt prototype was implemented in this paper adopting typical virtual machine monitor Xen. Compared with other work of the same kind, IVirt isolates the measurement software from the measured objects, preventing measurement software being attacked. On the other hand, address translation is employed to measure the runtime state, which is different from the method of using events intercepting, in order to reduce the performance overhead. The experimental results show that this method has the ability of detecting software modification, and it does not introduce high performance cost. ©, 2014, Science Press. All right reserved.
引用
收藏
相关论文
共 50 条
  • [21] A File Integrity Monitoring System Based on Virtual Machine
    Wang, Zhu
    Huang, Tao
    Wen, Sha
    PROCEEDINGS OF THE 2012 SECOND INTERNATIONAL CONFERENCE ON INSTRUMENTATION & MEASUREMENT, COMPUTER, COMMUNICATION AND CONTROL (IMCCC 2012), 2012, : 653 - 659
  • [22] Protecting Critical Files Using Target-Based Virtual Machine Introspection Approach
    Zhan, Dongyang
    Ye, Lin
    Fang, Binxing
    Du, Xiaojiang
    Xu, Zhikai
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2017, E100D (10): : 2307 - 2318
  • [23] QEMU-Based Framework for Non-intrusive Virtual Machine Instrumentation and Introspection
    Dovgalyuk, Pavel
    Fursova, Natalia
    Vasiliev, Ivan
    Makarov, Vladimir
    ESEC/FSE 2017: PROCEEDINGS OF THE 2017 11TH JOINT MEETING ON FOUNDATIONS OF SOFTWARE ENGINEERING, 2017, : 944 - 948
  • [24] Enforcing Access Controls for the Cryptographic Cloud Service Invocation Based on Virtual Machine Introspection
    Jiang, Fangjie
    Cai, Quanwei
    Guan, Le
    Lin, Jingqiang
    INFORMATION SECURITY (ISC 2018), 2018, 11060 : 213 - 230
  • [25] Towards Automated Characterization of Malware's High-level Mechanism using Virtual Machine Introspection
    Yonamine, Shun
    Kadobayashi, Youki
    Miyamoto, Daisuke
    Taenaka, Yuzo
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP), 2019, : 471 - 478
  • [26] Virtual environment based on accurate machine modeling
    不详
    FOREST PRODUCTS JOURNAL, 2000, 50 (04) : 8 - 8
  • [27] The Fraunhofer virtual machine: a communication library and runtime system based on the RDMA model
    Machado, Rui
    Lojewski, Carsten
    COMPUTER SCIENCE-RESEARCH AND DEVELOPMENT, 2009, 23 (3-4): : 125 - 132
  • [28] A Modified Bat Mechanism for Virtual Machine Migration in a Cloud Environment
    Narander Archana
    undefined Kumar
    SN Computer Science, 6 (1)
  • [29] AN INTEGRATED RUNTIME MONITORING METHOD FOR INTERNET-BASED VIRTUAL COMPUTING ENVIRONMENT
    Zhang, Hong
    Liu, Xinran
    Zhu, Chunge
    Liu, Qian
    2012 IEEE 2nd International Conference on Cloud Computing and Intelligent Systems (CCIS) Vols 1-3, 2012, : 481 - 487
  • [30] EPA-RIMM : An Efficient, Performance -Aware Runtime Integrity Measurement Mechanism for Modern Server Platforms
    Delgado, Brian
    Vibhute, Tejaswini
    Fastabend, John
    Karavanic, Karen
    2019 49TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN 2019), 2019, : 422 - 434