基于Xen虚拟化的隐藏进程检测方法  被引量:3

Method of detecting hidden process based on Xen virtualization

在线阅读下载全文

作  者:赵志远 朱智强[1] 孙磊[1] 杨杰[1] 

机构地区:[1]信息工程大学三院,郑州450000

出  处:《计算机应用研究》2015年第4期1127-1130,1153,共5页Application Research of Computers

基  金:国家"863"计划基金资助项目(2008AA01Z404);国防预研基金资助项目(910A26010306JB5201)

摘  要:恶意进程利用Rootkit使自己具有极强的隐蔽性。传统的隐藏进程检测工具部署在被检测系统中,容易受到攻击。为提高检测系统的抗攻击性和准确性,提出了一种虚拟环境下特征匹配的隐藏进程检测系统。该系统部署在被监控虚拟机外部,自调整检测频率扫描计算机内存来获取进程相关信息,并通过与预先构建好的特征模板进行相似度匹配,达到检测隐藏进程的目的。实验结果表明,该检测系统可以有效地检测出典型的Rootkit代码,确定隐藏进程的存在。Malicious processes are the major hidden danger to the safety of the computer system,which make themselves more hidden through the Rootkit. Conventional detection tools exist inside the very host they are protecting,which make them vulnerable to be attacked. In order to improve the ability and accuracy of tamper resistance,this paper designed a hidden process detection system using feature matching in virtual environment. By scanning machine memory directly and adjusting itself frequently,the system located outside the monitored virtual machine inspected the process information,and then achieved the purpose of detecting hidden process through judging the process information similar to the pre-framed feature template. Experimental results show that the detection system can effectively detect typical Rootkit code,determine the presence of hidden processes.

关 键 词:虚拟机监视器 隐藏进程 匹配特征 匹配模板 相似度匹配 检测频率 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象