节点文献
基于VMM的程序行为异常检测
Abnormality Detection of Program Behavior by Using VMM
【摘要】 虚拟机监视器(Virtual Machine Monitor,VMM)具有强隔离性、高透明性的特点,而程序行为具有稳定和易于检测的属性。提出了一种基于VMM的程序行为异常检测模型,该模型首先从VMM中捕获程序行为产生的底层数据,通过分析对进程行为视图重构,然后结合防护检查点,采用基于C4.5决策树算法对所重构的程序行为视图数据进行动态综合分析和判定,以此检测异常并警告。最后基于QEMU对检测模型进行实现并分析,结果表明该模型能有效检测出程序的异常行为。
【Abstract】 Considering that VMM(Virtual Machine Monitor) has the characteristics of strong isolation and high transparency,while program behavior which is stable and easy to be detected,a VMM-based behavior-abnormality detection model is proposed.The model could capture low-level data from the VMM layer and reconstruct them as up-level information,then automatically carry out comprehensive analysis on program behavior in combination of the protective checkpoints and C4.5 decision tree algorithm,thus to detect abnormal behaviors and give the warning.By using QEMU as VMM,the model is designed and implemented,and the experiment results show that the proposed model could detect the abnormal behavior effectively.
【Key words】 virtual machine monitor; software behavior; c4.5 decision tree;
- 【文献出处】 信息安全与通信保密 ,Information Security and Communications Privacy , 编辑部邮箱 ,2016年03期
- 【分类号】TP393.08
- 【被引频次】1
- 【下载频次】73