Journal of Beijing University of Posts and Telecommunications

  • EI核心期刊

JOURNAL OF BEIJING UNIVERSITY OF POSTS AND TELECOM ›› 2017, Vol. 40 ›› Issue (s1): 43-47.doi: 10.13190/j.jbupt.2017.s.010

• Papers • Previous Articles     Next Articles

A Security Protection Model for Virtualization Based on Memory Introspection

ZHANG Shu-hui1,2, MENG Xiang-xu1, WANG Lian-hai2, XU Shu-jiang2   

  1. 1. School of Computer Science and Technology, Shandong University, Jinan 250101, China;
    2. Shandong Provincial Key Laboratory of Computer Networks, Shandong Computer Science Center(National Supercomputer Center in Jinan), Jinan 250014, China
  • Received:2016-04-30 Online:2017-09-28 Published:2017-09-28

Abstract: A security protection module for virtualization based on memory introspection is proposed. By analyzing the physical memory of host machine, this model can detect running virtual machines in real time and reconstruct their high-level semantic information without any priori knowledge. Then, malicious activity in virtual machines can be identified timely and intelligent response will be made. Experimental results show that the system is transparent, attack-resistant, universal and efficient.

Key words: virtualization security, virtual machine introspection, memory introspection, memory analysis

CLC Number: