IVirt: Runtime environment integrity measurement mechanism based on virtual machine introspection

被引:0
|
作者
School of Computer Science, Beijing University of Posts and Telecommunications, Beijing [1 ]
100876, China
不详 [2 ]
100876, China
不详 [3 ]
100876, China
机构
来源
Jisuanji Xuebao | / 1卷 / 191-203期
关键词
D O I
10.3724/SP.J.1016.2015.00191
中图分类号
学科分类号
摘要
Integrity Measurement is an important method to detect compromised application, but under the virtualization environment traditional detection approaches have reflected some shortages. For example, the measurement software and measured objects are in the same operating system, so the measurement software is easily attacked. From the perspectives of security and performance, this paper proposes an integrity measurement mechanism based on virtual machine introspection-IVirt (Integrity for Virtualization). This mechanism obtains the needed memory data of virtual machine through address translation and content locating from outside of that virtual machine, thereby measuring the integrity of applications that are in the virtual machine is performed, so as to verify whether the applications are tampered with. The IVirt prototype was implemented in this paper adopting typical virtual machine monitor Xen. Compared with other work of the same kind, IVirt isolates the measurement software from the measured objects, preventing measurement software being attacked. On the other hand, address translation is employed to measure the runtime state, which is different from the method of using events intercepting, in order to reduce the performance overhead. The experimental results show that this method has the ability of detecting software modification, and it does not introduce high performance cost. ©, 2014, Science Press. All right reserved.
引用
收藏
相关论文
共 50 条
  • [41] Hash Tree Based Trustworthiness Verification Mechanism in Virtual Environment
    Zhu Shuaishuai
    Han Yiliang
    Yang Xiaoyuan
    Wei Yuechuan
    CHINA COMMUNICATIONS, 2016, 13 (03) : 184 - 192
  • [42] Research on Dynamic Integrity Measurement Model Based on Memory Paging Mechanism
    Chang, Chaowen
    Chen, Xin
    Wang, Shuai
    Xiao, Qinghai
    DISCRETE DYNAMICS IN NATURE AND SOCIETY, 2014, 2014
  • [43] Cloud data security and integrity protection model based on distributed virtual machine agents
    Xu, Xiaolong
    Liu, Guangpei
    Zhu, Jie
    2016 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY PROCEEDINGS - CYBERC 2016, 2016, : 6 - 13
  • [44] USABILITY TEST IN A VIRTUAL ENVIRONMENT, A CASE STUDY BASED ON A MINING MACHINE
    Yousefi, Hassan
    Handroos, Heikki
    Soleimani, Amir
    PROCEEDINGS OF THE ASME 10TH BIENNIAL CONFERENCE ON ENGINEERING SYSTEMS DESIGN AND ANALYSIS, 2010, VOL 4, 2010, : 603 - 611
  • [45] A Dynamic Placement Policy of Virtual Machine Based on MOGA in Cloud Environment
    Zhang, Mohan
    Ren, Honglin
    Xia, Chunhe
    2017 15TH IEEE INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED PROCESSING WITH APPLICATIONS AND 2017 16TH IEEE INTERNATIONAL CONFERENCE ON UBIQUITOUS COMPUTING AND COMMUNICATIONS (ISPA/IUCC 2017), 2017, : 885 - 891
  • [46] Virtual Machine Security Migration Strategy Based on the Edge Computing Environment
    Du, Ruizhong
    He, Wangkai
    Tian, Junfeng
    2020 16TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING (MSN 2020), 2020, : 803 - 808
  • [47] Network Traffic based Virtual Machine Migration in Cloud Computing Environment
    Fu, Xiong
    Zhang, Congyue
    Chen, Juzhou
    Zhang, Lin
    Qiao, Lei
    PROCEEDINGS OF 2019 IEEE 3RD INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2019), 2019, : 818 - 821
  • [48] Virtual light sensors in industrial environment based on machine learning algorithms
    Drakoulelis, Michalis
    Filios, Gabriel
    Ninos, Vasilis Georgopoulos
    Katsidimas, Ioannis
    Nikoletseas, Sotiris
    2019 15TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING IN SENSOR SYSTEMS (DCOSS), 2019, : 709 - 716
  • [49] A BLP-based Access Control Mechanism for the Virtual Machine System
    Weng, Chuliang
    Luo, Yuan
    Li, Minglu
    Lu, Xinda
    PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE FOR YOUNG COMPUTER SCIENTISTS, VOLS 1-5, 2008, : 2278 - 2282
  • [50] A virtual machine migration mechanism based on firefly optimization for cloud computing
    Singh S.
    Singh D.
    Recent Patents on Engineering, 2021, 15 (04)