Malware detection for container runtime based on virtual machine introspection

被引:0
|
作者
He, Xinfeng [1 ,2 ]
Li, Riyang [1 ,2 ]
机构
[1] Hebei Univ, Sch Cyber Secur & Comp, Baoding 071002, Peoples R China
[2] Key Lab High Trusted Informat Syst Hebei Prov, Baoding 071002, Peoples R China
来源
JOURNAL OF SUPERCOMPUTING | 2024年 / 80卷 / 06期
关键词
Container; Virtual machine introspection; Container escape; Convolutional neural network; Malware detection;
D O I
10.1007/s11227-023-05727-w
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The isolation technique of containers introduces uncertain security risks to malware detection in the current container environment. In this paper, we propose a framework called Malware Detection for Container Runtime based on Virtual Machine Introspection (MDCRV) to detect in-container malware. MDCRV can automatically export the memory snapshots by using virtual machine introspection in container-in-virtual-machine architecture and reconstruct container semantics from memory snapshots. Although in-container malware might escape from the isolating measures of the container, our detecting program which benefits from the isolation of the hypervisor still can work well. Additionally, we propose a container process visualization approach to improve the efficiency of analyzing the binary execution information of container runtime. We convert the live processes of in-container malware and benign application to grayscale images and employ the convolutional neural network to extract malware features from the self-constructed dataset. The experimental results show that MDCRV achieves high accuracy while improving security.
引用
收藏
页码:7245 / 7268
页数:24
相关论文
共 50 条
  • [1] Malware detection for container runtime based on virtual machine introspection
    Xinfeng He
    Riyang Li
    The Journal of Supercomputing, 2024, 80 (6) : 7245 - 7268
  • [2] IVirt: Runtime environment integrity measurement mechanism based on virtual machine introspection
    School of Computer Science, Beijing University of Posts and Telecommunications, Beijing
    100876, China
    不详
    100876, China
    不详
    100876, China
    Jisuanji Xuebao, 1 (191-203):
  • [3] Memory Forensics Using Virtual Machine Introspection for Malware Analysis
    Tien, Chin-Wei
    Liao, Jian-Wei
    Chang, Shun-Chieh
    Kuo, Sy-Yen
    2017 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING, 2017, : 518 - 519
  • [4] Virtual Machine Introspection for Anomaly-Based Keylogger Detection
    Huseynov, Huseyn
    Kourai, Kenichi
    Saadawi, Tarek
    Igbe, Obinna
    2020 IEEE 21ST INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE SWITCHING AND ROUTING (IEEE HPSR), 2020,
  • [5] Developing a novel methodology for virtual machine introspection to classify unknown malware functions
    Rahul N. Vaza
    Ramesh Prajapati
    Dushyantsinh Rathod
    Dineshkumar Vaghela
    Peer-to-Peer Networking and Applications, 2022, 15 : 793 - 810
  • [6] Developing a novel methodology for virtual machine introspection to classify unknown malware functions
    Vaza, Rahul N.
    Prajapati, Ramesh
    Rathod, Dushyantsinh
    Vaghela, Dineshkumar
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2022, 15 (01) : 793 - 810
  • [7] Android Malware Detection Based on Runtime Behaviour
    Aktas, Kursat
    Sen, Sevil
    2018 26TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2018,
  • [8] Insider Threat Detection using Virtual Machine Introspection
    Crawford, Martin
    Peterson, Gilbert
    PROCEEDINGS OF THE 46TH ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES, 2013, : 1821 - 1830
  • [9] Analysis of Mobility Algorithms for Forensic Virtual Machine Based Malware Detection
    Alruhaily, Nada
    Bordbar, Behzad
    Chothia, Tom
    2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 766 - 773
  • [10] Machine-Learning-Based Malware Detection for Virtual Machine by Analyzing Opcode Sequence
    Wang, Xiao
    Zhang, Jianbiao
    Zhang, Ai
    ADVANCES IN BRAIN INSPIRED COGNITIVE SYSTEMS, BICS 2018, 2018, 10989 : 717 - 726