Detecting malware signatures in a thin hypervisor

Detecting malware signatures in a thin hypervisor
复制标题

检测瘦虚拟机​​管理程序中的恶意软件签名

DOI:
--
复制
发表时间:
2012
期刊:
ACM Symposium on Applied Computing
影响因子:
--
通讯作者:
Kazuhiko Kato
Kazuhiko Kato
中科院分区:
--
文献类型:
--
作者:
Y. Oyama;Tran Truong Duc Giang;Yosuke Chubachi;Takahiro Shinagawa;Kazuhiko Kato

文献摘要

被引文献

相似文献

使用管理程序增强安全性是一种被广泛研究的有效方法。本文关注的是使用透传架构的管理程序,在这种架构中,来自操作系统的大多数I/O访问都通过管理程序,而实现安全功能所需的最小访问则由管理程序进行调解。直通管理程序可以提供各种安全功能,如存储数据加密和创建虚拟专用网络。尽管之前的一项研究详细介绍了通过旁通管理程序保护隐私的方法,但尚未阐明检测恶意软件的方法。在本文中,我们提出了一种将恶意软件检测功能合并到旁路管理程序中的方案。使用这个方案,我们实现了BVMD,一个通过旁传管理程序BitVisor的扩展,用于恶意软件检测。BVMD通过将数据I/O的内容与恶意软件签名进行比较来检测恶意软件。BVMD的一个主要优点是它的检测只稍微依赖于客户机操作系统。我们通过实验证实,BVMD可以检测到许多野外恶意软件。
Enhancement of security using hypervisors is an effective approach that has been extensively studied. This paper is concerned with hypervisors using the parapass-through architecture, in which most of the I/O accesses from the operating system are passed through the hypervisor, while the minimum accesses necessary to implement security functionality are mediated by the hypervisor. Parapass-through hypervisors can provide various security functionalities such as encryption of storage data and creation of virtual private networks. Although a previous study has detailed a method for protecting privacy with a parapass-through hypervisor, it has not yet clarified a method for detecting malware. In this paper, we propose a scheme for incorporating malware detection functionality into a parapass-through hypervisor. Using this scheme, we implemented BVMD, an extension of a parapass-through hypervisor BitVisor, for malware detection. BVMD detects malware by comparing the contents of the data I/O with the malware signatures. A major advantage of BVMD is that its detection depends only slightly on the guest operating system. We confirmed through experiments that BVMD could detect many in-the-wild malware.