首页 | 本学科首页   官方微博 | 高级检索  
     检索      

虚拟机自省中一种消除语义鸿沟的方法
引用本文:崔超远,乌 云,李 平,张晓明.虚拟机自省中一种消除语义鸿沟的方法[J].通信学报,2015,36(8):31-37.
作者姓名:崔超远  乌 云  李 平  张晓明
作者单位:1. 中国科学院 合肥智能机械研究所,安徽 合肥 230031; 2. 中国科学院 安徽循环经济技术工程院,安徽 合肥 230088;3. 中国科学技术大学 自动化系,安徽 合肥 230027
基金项目:中国科学院合肥物质科学研究院院长基金资助项目(YZJJ201329);国家自然科学基金资助项目(31171456, 61203373)
摘    要:虚拟机自省技术已经广泛应用于入侵检测和恶意软件分析等领域。但是由于语义鸿沟的存在,获取虚拟机内部信息时会导致其通用性和执行效率降低。通过分析现有语义鸿沟修复技术的不足,提出了一种称为ModSG的语义鸿沟消除方法。ModSG是一个模块化系统,将语义修复分为2部分:与用户直接交互的在线语义视图构建和与操作系统知识交互的离线高级语义解析。二者以独立的模块实现且后者为前者提供语义重构时必要的内核语义信息。针对不同虚拟机状态和不同内核版本操作系统的实验表明,ModSG在消除语义鸿沟上是准确和高效的。模块化设计和部署也使ModSG容易扩展到其他操作系统和虚拟化平台上。

关 键 词:语义鸿沟  虚拟机自省  模块化系统  可移植性
收稿时间:2014/2/13 0:00:00

Narrowing the semantic gap in virtual machine introspection
Chao-yuan CUI,Yun WU,Ping LI,Xiao-ming ZHANG.Narrowing the semantic gap in virtual machine introspection[J].Journal on Communications,2015,36(8):31-37.
Authors:Chao-yuan CUI  Yun WU  Ping LI  Xiao-ming ZHANG
Institution:1. Institute of Intelligent Machines,CAS,Hefei 230031,China;2. Anhui Technology and Engineering Institute for Recycling Economy,CAS,Hefei 230088,China;3. Department of Automation,University of Science and Technology of China,Hefei 230027,China
Abstract:Virtual machine introspection(VMI) has been widely used in areas such as intrusion detection and malware analysis. However, due to the existence of semantic gap, the generality and the efficiency of VMI were partly influenced while getting internal information of a virtual machine. By analyzing the deficiencies of existing technology of semantic gap restoration, a method called ModSG was proposed to bridge the semantic gap. ModSG was a modularity system, it divided semantic restoration into two parts. One was online phase that interact directly with user to construct semantic views, the other was offline phase that only interact with operating system to parse high-level semantic knowledge. Both were implemented via independent module, and the latter provided the former with necessary kernel information during semantic view construction. Experiments on different virtual machine states and different kernel versions show that the ModSG is accurate and efficient in narrowing semantic gap. The modular design and deployment also make ModSG easily to be extended to other operating systems and virtualization platforms.
Keywords:semantic gap  virtual machine introspection  modularity system  portability
点击此处可从《通信学报》浏览原始摘要信息
点击此处可从《通信学报》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号