Hidden Process Detection System Based on Hardware-Assisted Virtualization

Xuexiang Li, Xuemei An, Wenning Zhang
{"title":"Hidden Process Detection System Based on Hardware-Assisted Virtualization","authors":"Xuexiang Li, Xuemei An, Wenning Zhang","doi":"10.1109/ICICSE.2013.17","DOIUrl":null,"url":null,"abstract":"Hidden process detection is an important issue in information security area. Based on hardware-assisted virtualization, the system proposed in this paper can monitor guest operating system (Guest OS) via the highest privilege level of Virtual Machine Monitor (VMM). It realizes functions of detection, creation monitoring and termination of hidden processes, even for malicious Root kit processes in kernel. Comparing to popular process detection tools using hook functions or relying on unpublicized data structures, the optimized system doesn't depend on any hook function and destroy any data structure of OS, making it much more efficient and better in the area of hidden processes detection.","PeriodicalId":111647,"journal":{"name":"2013 Seventh International Conference on Internet Computing for Engineering and Science","volume":"5 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-09-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 Seventh International Conference on Internet Computing for Engineering and Science","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICICSE.2013.17","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Hidden process detection is an important issue in information security area. Based on hardware-assisted virtualization, the system proposed in this paper can monitor guest operating system (Guest OS) via the highest privilege level of Virtual Machine Monitor (VMM). It realizes functions of detection, creation monitoring and termination of hidden processes, even for malicious Root kit processes in kernel. Comparing to popular process detection tools using hook functions or relying on unpublicized data structures, the optimized system doesn't depend on any hook function and destroy any data structure of OS, making it much more efficient and better in the area of hidden processes detection.
基于硬件辅助虚拟化的隐藏进程检测系统
隐藏进程检测是信息安全领域的一个重要问题。本文提出的系统基于硬件辅助虚拟化,可以通过虚拟机监控(VMM)的最高权限级别对来宾操作系统(guest OS)进行监控。在内核中实现了对隐藏进程的检测、创建、监控和终止等功能,甚至对恶意rootkit进程也是如此。与使用钩子函数或依赖于未公开数据结构的流行进程检测工具相比,优化后的系统不依赖于任何钩子函数,也不破坏操作系统的任何数据结构,在隐藏进程检测方面效率更高,性能更好。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信