课题基金 / 基金详情

Collaborative Research: II-NEW: OpenVMI: A Software Instrument for Virtual Machine Introspection

Collaborative Research: II-NEW: OpenVMI: A Software Instrument for Virtual Machine Introspection
协作研究:II-新:OpenVMI:用于虚拟机自省的软件工具
批准号:
0855036
负责人:
Xuxian Jiang
金额:
$22.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-01 至 2014-08-31

项目摘要

项目成果

Xuxian Jiang的其他基金

相似基金

相关文献

中文摘要
翻译
提案标题:协作研究:II-新:OpenVMI:用于虚拟机内省的软件工具机构:普渡大学摘要日期:07/09/09本项目开发了OpenVMI,这是一种用于虚拟机内省(VMI)的开源、基于软件的研究工具。VMI对分布式计算、自动化系统管理与配置、计算机安全等研究具有重要意义,虚拟化技术为分布式计算、自动化系统管理与配置、计算机安全等领域的研究创造了新的契机。在基于虚拟化的研究中,一个基本但功能强大的工具功能是虚拟机自省(VMI):从VM外部观察VM的语义状态和事件。VMI很难实现,这主要是因为VMI的外部和内部观察之间的语义差距。因此,通用的VMI软件工具变得非常受虚拟化研究人员的欢迎。本项目开发并部署了OpenVMI,这是普渡大学和北卡罗来纳州立大学针对VMI的开源、基于软件的研究工具。OpenVMI可以被认为是一种?透视?适用于VM的工具。通过OpenVMI API,用户可以在不修改或插装VM的情况下获得内核和用户空间中的VM?S语义状态和事件。将从OpenVMI的开发和部署中受益的机构:-托管虚拟环境的管理:这项研究涉及监控、配置和管理在共享的分布式托管基础设施中运行的自主虚拟环境。Open-VMI将实现对VM的非侵入性、语义监控,这将在运行时触发VM管理操作,如VM迁移、资源适配和访问控制。-监视、检测和调查用户级恶意软件:本研究涉及用于恶意软件检测和调查的OS级策略和机制。通过使用OpenVMI,可以将这些策略和机制移出目标VM,在不损失VM可观察性的情况下实现更强的防篡改。-操作系统完整性监控:本研究旨在解决来宾操作系统针对内核级攻击的完整性问题。它还涉及对内核级攻击的详细分析,以供将来检测和恢复。OpenVMI将提供一个独特的时间点来观察内核对象的实时状态变化,这将有助于揭示操作系统完整性冲突的细节。以上领域的六个研究项目被指定为OpenVMI部署。国家科学基础建议摘要建议:0855141 PI姓名:徐,东燕从eJacket打印:07/25/09第1页,共1页
英文摘要
Proposal Title: Collaborative Research: II-New: OpenVMI: A Software Instrumentfor Virtual Machine IntrospectionInstitution: Purdue UniversityAbstract Date: 07/09/09This project develops the OpenVMI, an open-source, software-based researchinstrument for virtual machine introspection (VMI). VMI is important to certain researchareas such as distributed computing, automated system management andconfiguration, and computer security.Virtualization technologies have created new momentumfor a number of research areassuch as distributed computing, automated system management and configuration, andcomputer security. One basic yet powerful instrumentation function invirtualization-based research is virtual machine introspection (VMI): observing a VM?ssemantic states and events from outside the VM. VMI is hard to implement, mainlybecause of the semantic gap between the external and internal observations of the VM.Thus a generic VMI software instrument becomes highly desirable to virtualizationresearchers.This project develops and deploys OpenVMI, an open-source, software-based researchinstrument for VMI at Purdue University and North Carolina State University. OpenVMIcan be thought of as a ?fluoroscopic? instrument for VMs. Through the OpenVMI API, auser will be able to obtain the VM?s semantic states and events in both kernel and userspaces without modifying or instrumenting the VM.Three research areas are identified at the PIs? institutions that will benefit from thedevelopment and deployment of OpenVMI:-Management of hosted virtual environments: This research involves monitoring,provisioning and regulating autonomous virtual environments running in a shareddistributed hosting infrastructure. Open- VMI will enable non-intrusive, semanticmonitoring of VMs, which will trigger VM management operations at runtime such asVM migration, resource adaptation and access control.-Monitoring, detection and investigation of user-level malware: This research isconcerned with OSlevel policies and mechanisms for malware detection andinvestigation. By using OpenVMI, these policies and mechanisms can be moved out ofthe target VM, achieving stronger tamper-resistance without losing VM observability.-Monitoring of OS integrity: This research addresses the integrity of the guest OSagainst kernel-level attacks. It also involves detailed profiling of kernel-level attacks forfuture detection and recovery. OpenVMI will provide a unique vintage point to observeruntime state changes of kernel objects, which will help reveal details of an OS integrityviolation.Six research projects in the above areas are designated for OpenVMI deployment.NATIONAL SCIENCE FOUNDATIONProposal AbstractProposal:0855141 PI Name:Xu, DongyanPrinted from eJacket: 07/25/09 Page 1 of 1
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CAREER: Towards Exterminating Stealthy Rootkits - A Systematic Immunization Approach
  • 批准号:
    0952640
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $42.42万
  • 财政年份:
    2010
  • 负责人:
    Xuxian Jiang
  • 依托单位:
CT-ISG: Understanding Botnet Command and Control (C&C) Communication
  • 批准号:
    0831160
  • 项目类别:
    Standard Grant
  • 资助金额:
    $0.0万
  • 财政年份:
    2008
  • 负责人:
    Xuxian Jiang
  • 依托单位:
CT-ISG: Collaborative: Enabling Detection of Elusive Malware by by Going Out of the Box with Semantically Reconstructed View (OBSERV)
  • 批准号:
    0852131
  • 项目类别:
    Standard Grant
  • 资助金额:
    $20.26万
  • 财政年份:
    2008
  • 负责人:
    Xuxian Jiang
  • 依托单位:
CT-ISG: Understanding Botnet Command and Control (C&C) Communication
  • 批准号:
    0855297
  • 项目类别:
    Standard Grant
  • 资助金额:
    $40.0万
  • 财政年份:
    2008
  • 负责人:
    Xuxian Jiang
  • 依托单位:
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)