节点文献

一种基于Xen虚拟机的内核完整性监控方法

A Kernel Integrity Monitoring Method Based on Xen Virtual Machine

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 徐靖徐海水

【Author】 XU Jing;XU Hai-shui;Faculty of Computer, Guangdong University of Technology;

【机构】 广东工业大学计算机学院

【摘要】 为了防止内核级Rootkit对内核完整性造成破坏,描述基于Xen的隔离保护方法,Xen是一种微内核结构的虚拟机,直接运行在硬件之上,操作系统内核在Xen的域里运行,而域又可分为权限域Dom0和非权限域DomU,域间相互隔离,利用这个特性,强制将动态加载模块隔离在DomU里运行,并通过Xen的事件通道和授权表两个域间通信机制模拟出模块与内核之间函数调用。将监视模块加入中间层就可以达到监控所有模块对内核的操作。

【Abstract】 To prevent kernel-level Rootkit damage the integrity of kernel, describes a Xen-based isolation protection approach. Xen is a macro-kernel structural virtual machine, which runs directly on top of the hardware. Operating system kernel can run inside the Domain of Xen,Domains can be divided into two categories: privilege domain Dom0 and non-privilege domain DomU, which will be mutual isolated between each other. Takes the advantage of the isolated feature, Loadable Kernel Modules will be forced to run inside an isolated DomU,and function call between module and core kernel will be simulated by a middle layer which can be achieved by Xen’s inter-domain communication interface: Event Channel and Grant Table. Monitor modules can be added into the middle layer to monitor all operations from modules to kernel.

【基金】 广东省可信网络行为模型与机制的研究项目(No.07001802)
  • 【文献出处】 现代计算机(专业版) ,Modern Computer , 编辑部邮箱 ,2014年14期
  • 【分类号】TP302
  • 【被引频次】3
  • 【下载频次】86
节点文献中: