跳到主要导航 跳到搜索 跳到主要内容

Software integrity verification based on VMM-Level system call analysis technique

  • Beihang University

科研成果: 期刊稿件文章同行评审

摘要

In virtualized cloud computing platform, the key security problem is to guarantee trustworthiness of the softwares which are running in the platform. Integrity measurement and verification has been proposed and studied by many researchers as an effective way to verify the integrity of computer systems. However, existing approaches have some limitations on compatibility, security and maintainability, and cannot be applied into the cloud computing platform. In this paper, we propose a approach named VMGuard, which leverages VMM to enable take integrity measurement outside the operating system. We adopt VMM-based system call interception technique to detect the execution of binaries. System call correlation and guest OS file system metadata reconstruction are proposed to verify the integrity of software in guest OS. We have developed a prototype of VMGuard and implemented it in two mainstream virtual machine monitors, Qemu and KVM, respectively. We also evaluate the effectiveness and performance overhead of our approach by comprehensive experiments. The results show that VMGuard achieves effective integrity measurement with less than 10% overhead.

源语言英语
页(从-至)1438-1446
页数9
期刊Jisuanji Yanjiu yu Fazhan/Computer Research and Development
48
8
出版状态已出版 - 8月 2011

学术指纹

探究 'Software integrity verification based on VMM-Level system call analysis technique' 的科研主题。它们共同构成独一无二的学术指纹。

引用此