基于硬件虚拟化技术的跨平台安全保护分析-analysis of cross-platform security protection based on hardware virtualization technology.docxVIP
- 19
- 0
- 约4.86万字
- 约 67页
- 2018-08-14 发布于上海
- 举报
基于硬件虚拟化技术的跨平台安全保护分析-analysis of cross-platform security protection based on hardware virtualization technology
机监控程序来监控在操作系统下各种不同的恶意行为,称为VASP。该平台主要体现了三大创新优点。首先,该保护平台是一个轻量级的低系统开销的虚拟机监控平台。利用了代码优化,最大限度地降低了虚拟机监控程序的大小,从而减小了可信计算基础的体积,使得监控层更加安全有效。并且在保护过程中尽量减少对操作系统执行过程的影响,使得监控开销降到最低。其次,本课题实现的保护机制提供了跨操作系统平台的支持,并且在多数保护过程中无需修改操作系统源代码。在实现过程中,VASP仅仅需要根据操作系统中调用锁机制以及内存分配机制的相关API函数进行匹配执行,其余的代码都和操作系统平台无关。在监控拦截过程中得益于x86的硬件虚拟化技术,使得拦截行为都由CPU硬件完成,无需软件参与。最后,VASP保护平台可以提供对多种系统保护的支持,包括I/O访问保护、系统反调试保护以及内存访问保护等。并且还可以在这个基础上通过增加系统功能的形式,扩展添加更多的系统保护机制。同时,VASP也实现了自我保护机制,即内存自透明技术。该机制可以使得虚拟机监控程序无法被虚拟机操作系统通过虚拟内存访问来发现自身的存在。本次论文课题的设计目的在于建立一个完全驻留于操作系统运行环境以外的极小开销的安全监控程序。通过实验可以证明基于硬件虚拟化的跨平台安全保护机制能够有效地防止某些恶意行为的侵害,并可以对不同操作系统平台,如WindowsXP和FedoraLinux,提供安全保护,而且只减少了微小的系统开销。关键词:硬件虚拟化,跨平台,安全保护,内存自透明HardwareVirtualizationassistedSecurityMonitorforCross-PlatformProtectionABSTRACTNumerousoperatingsystemshavebeendesignedtomanageandcontrolsystemresourceswithlargeandcomplicatedfeatures,sotheyneedhighsecurityprotection.However,previoussecurityapplicationscannotprovideadequateprotectionduetotheuntrustedexecutionenvironment.Furthermore,thesesecuritystrategiescannotsupportauniversalcross-platformsystemsecurityrequirement.Besides,differentcommodityoperatingsystemsanddifferentopensourceoperatingsystemshavetheirowndesignarchitecturesandimplementation,sotraditionalsecurityprotectionneedtoadapttothosedifferentOSes.Forthecurrentlackofsecurity,thissubjectusehardwarevirtualizationtechnologytoachievethelightweight,effectiveandcross-platformsystemprotection.Virtualizationtechnologycouldmakeahighdegreeisolationbetweenvirtualmachineandvirtualmachinemonitor.Althoughvirtualmachineisrunningunderauntrustedexecutionenvironment,thatwillnotaffectthemonitor.Furthermore,thevirtualmachinemonitorisunderahigherprivilegethanguestoperatingsystemis,soitcanmonitortheexecutionofvirtualmachineandgetmorehardwareresources.Nomatterwhichprivilegeofoperatingsystemthemaliciouscodeworkson,themonitorhavethepowertodetectandstopit,butapplicationswhicharerunningontheoperatingsystemcan’tdetecttheexistenceofthemonitor.ThispaperpresentsVASP,ahypervisorbasedmonitorwhichallow
您可能关注的文档
- 基于虚拟样机技术新型矿山防跑车限速车轮设计-design of new mine anti-speed limit wheel based on virtual prototype technology.docx
- 基于虚拟样机水稻田双螺旋式整梗机研制-research and development of double screw type stalk machine for paddy field based on virtual prototype.docx
- 基于虚拟仪器的小型断路器瞬动特性的检测技术分析-analysis of detection technology for instantaneous characteristics of small circuit breaker based on virtual instrument.docx
- 基于虚拟仪器构架的电子测量工作站软件集成技术分析-software integration technology analysis of electronic measurement workstation based on virtual instrument framework.docx
- 基于虚拟仪器技术激光修整超硬磨料砂轮测控系统设计-design of laser dressing ultra-hard abrasive wheel measurement and control system based on virtual instrument technology.docx
- 基于需求侧响应的电动汽车有序充电分析-analysis of orderly charging of electric vehicles based on demand side response.docx
- 基于需求分析的高职英语课堂分层教学设计——以《走出牛津》unit2模块i为例-hierarchical teaching design of english classes in higher vocational colleges based on demand analysis - taking unit 2 module i in.docx
- 基于需求分析的景区员工培训设计及其效果评估研究——以西樵山风景名胜区为例-research on staff training design and effect evaluation of scenic spots based on demand analysis - a case study of xiqiao mountain scenic spot.docx
- 基于需求分析的社区英语课程开发研究——以上海市闵行区诸翟镇华漕社区为例-research on the development of community english curriculum based on demand analysis a case study of huacao community in zhuzhai town, minhang district, shanghai.docx
- 基于需求分析理论的商务英语课程设置研究——以山东交通学院为例-research on the curriculum design of business english based on demand analysis theory - taking shandong jiaotong university as an example.docx
原创力文档

文档评论(0)