VMScan: an out-of-VM malware scanner  

在线阅读下载全文

作  者:Lin Jie Liu Chuanyi Fang Binxing 

机构地区:[1]School of Computer Science and Technology,Harbin Institute of Technology,Shenzhen,Shenzhen 518055,China [2]Key Laboratory of Trustworthy Distributed Computing and Service,Beijing University of Posts and Telecommunications,Beijing 100876,China [3]Department of Information and Electronic Engineering,Chinese Academy of Engineering,Beijing 100088,China

出  处:《The Journal of China Universities of Posts and Telecommunications》2020年第4期59-68,共10页中国邮电高校学报(英文版)

基  金:supported by the National Key Research and Development Program of China ( 2018YFB1004005 );the Key Research and Development Program of Guangdong Province ( 2019B010136001 );the National Natural Science Foundation of China ( 61872110)。

摘  要:The harm caused by malware in cloud computing environment is more and more serious. Traditional anti-virus software is in danger of being attacked when it is deployed in virtual machine on a large scale, and it tends not to be accepted by tenants in terms of performance. In this paper, a method of scanning malicious programs outside the virtual machine is proposed, and the prototype is implemented. This method transforms the memory of the virtual machine to the host machine so that the latter can access it. The user space and kernel space of virtual machine memory are analyzed via semantics, and suspicious processes are scanned by signature database. Experimental results show that malicious programs can be effectively scanned outside the virtual machine, and the performance impact on the virtual machine is low, meeting the needs of tenants.

关 键 词:security VIRTUALIZATION cloud MALWARE VIRUS detection SIGNATURE scanning 

分 类 号:TP302[自动化与计算机技术—计算机系统结构] TP311.53[自动化与计算机技术—计算机科学与技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象