节点文献

基于VMM的程序行为异常检测

Abnormality Detection of Program Behavior by Using VMM

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 蒋传勇姚立红潘理

【Author】 JIANG Chuang-yong;YAO Li-hong;PAN Li;School of Electronic Information and Electrical Engineering,Shanghai Jiaotong University;Key Lab of Integrated Management of Information Security;State Key Lab.for Novel Software Technology,Nanjing University;

【机构】 上海交通大学电子信息与电气工程学院上海市信息安全综合管理技术研究重点实验室南京大学计算机软件新技术国家重点实验室

【摘要】 虚拟机监视器(Virtual Machine Monitor,VMM)具有强隔离性、高透明性的特点,而程序行为具有稳定和易于检测的属性。提出了一种基于VMM的程序行为异常检测模型,该模型首先从VMM中捕获程序行为产生的底层数据,通过分析对进程行为视图重构,然后结合防护检查点,采用基于C4.5决策树算法对所重构的程序行为视图数据进行动态综合分析和判定,以此检测异常并警告。最后基于QEMU对检测模型进行实现并分析,结果表明该模型能有效检测出程序的异常行为。

【Abstract】 Considering that VMM(Virtual Machine Monitor) has the characteristics of strong isolation and high transparency,while program behavior which is stable and easy to be detected,a VMM-based behavior-abnormality detection model is proposed.The model could capture low-level data from the VMM layer and reconstruct them as up-level information,then automatically carry out comprehensive analysis on program behavior in combination of the protective checkpoints and C4.5 decision tree algorithm,thus to detect abnormal behaviors and give the warning.By using QEMU as VMM,the model is designed and implemented,and the experiment results show that the proposed model could detect the abnormal behavior effectively.

【基金】 国家科技支撑计划课题(No.2014BAG01B02)
  • 【文献出处】 信息安全与通信保密 ,Information Security and Communications Privacy , 编辑部邮箱 ,2016年03期
  • 【分类号】TP393.08
  • 【被引频次】1
  • 【下载频次】73
节点文献中: 

本文链接的文献网络图示:

本文的引文网络