Collaborative Research: II-New: OpenVMI: A Software Instrument for Virtual Machine Introspection
Collaborative Research: II-New: OpenVMI: A Software Instrument for Virtual Machine Introspection
批准号:
0855141
负责人:
Dongyan Xu
金额:
$25.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-01 至 2014-08-31
中文摘要
该项目开发了OpenVMI,一个开源的、基于软件的虚拟机自省(VMI)研究工具。VMI对于分布式计算、自动化系统管理和配置以及计算机安全等研究领域具有重要意义。虚拟化技术为分布式计算、自动化系统管理和配置以及计算机安全等许多研究领域创造了新的动力。在基于虚拟化的研究中,一个基本而强大的工具功能是虚拟机自省(VMI):观察虚拟机?从虚拟机外部获取语义状态和事件。VMI很难实现,主要是因为VM的外部和内部观察之间的语义差距。因此,一个通用的VMI软件仪器成为虚拟化研究人员非常需要的。该项目开发和部署OpenVMI,这是普渡大学和北卡罗莱纳州立大学为VMI开发的一个开源的、基于软件的研究工具。OpenVMI可以被认为是一种透视法。虚拟机仪表。通过OpenVMI API,用户将能够获得虚拟机?在不修改或检测VM的情况下,在内核和用户空间中的语义状态和事件。在pi中确定了三个研究领域。-托管虚拟环境的管理:本研究涉及监控、供应和调节在共享分布式托管基础设施中运行的自治虚拟环境。Open- VMI将支持对虚拟机的非侵入式语义监控,这将在运行时触发虚拟机管理操作,如虚拟机迁移、资源适配和访问控制。-监控、检测和调查用户级恶意软件:本研究关注的是os级恶意软件检测和调查的策略和机制。通过使用OpenVMI,可以将这些策略和机制移出目标VM,在不失去VM可观察性的情况下实现更强的防篡改能力。-监控操作系统的完整性:这项研究解决了客户操作系统的完整性,防止内核级攻击。它还包括对内核级攻击的详细分析,以便将来检测和恢复。OpenVMI将提供一个独特的复古点来观察内核对象的运行时状态变化,这将有助于揭示操作系统完整性冲突的细节。上述领域的六个研究项目被指定用于OpenVMI的部署。
英文摘要
This project develops the OpenVMI, an open-source, software-based research instrument for virtual machine introspection (VMI). VMI is important to certain research areas such as distributed computing, automated system management and configuration, and computer security.Virtualization technologies have created new momentumfor a number of research areas such as distributed computing, automated system management and configuration, and computer security. One basic yet powerful instrumentation function in virtualization-based research is virtual machine introspection (VMI): observing a VM?s semantic states and events from outside the VM. VMI is hard to implement, mainly because of the semantic gap between the external and internal observations of the VM. Thus a generic VMI software instrument becomes highly desirable to virtualization researchers. This project develops and deploys OpenVMI, an open-source, software-based research instrument for VMI at Purdue University and North Carolina State University. OpenVMI can be thought of as a ?fluoroscopic? instrument for VMs. Through the OpenVMI API, a user will be able to obtain the VM?s semantic states and events in both kernel and user spaces without modifying or instrumenting the VM. Three research areas are identified at the PIs? institutions that will benefit from the development and deployment of OpenVMI:-Management of hosted virtual environments: This research involves monitoring, provisioning and regulating autonomous virtual environments running in a shared distributed hosting infrastructure. Open- VMI will enable non-intrusive, semantic monitoring of VMs, which will trigger VM management operations at runtime such as VM migration, resource adaptation and access control. -Monitoring, detection and investigation of user-level malware: This research is concerned with OSlevel policies and mechanisms for malware detection and investigation. By using OpenVMI, these policies and mechanisms can be moved out of the target VM, achieving stronger tamper-resistance without losing VM observability. -Monitoring of OS integrity: This research addresses the integrity of the guest OS against kernel-level attacks. It also involves detailed profiling of kernel-level attacks for future detection and recovery. OpenVMI will provide a unique vintage point to observe runtime state changes of kernel objects, which will help reveal details of an OS integrity violation. Six research projects in the above areas are designated for OpenVMI deployment.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Medium: Collaborative: Threat-Aware Defense: Evaluating Threats for Continuous Improvement
-
批准号:1801601
-
项目类别:Standard Grant
-
资助金额:$39.98万
-
财政年份:2018
-
负责人:Dongyan Xu
-
依托单位:
TWC: Medium: Collaborative: Towards a Binary-Centric Framework for Cyber Forensics in Enterprise Environments
-
批准号:1409668
-
项目类别:Standard Grant
-
资助金额:$80.0万
-
财政年份:2014
-
负责人:Dongyan Xu
-
依托单位:
NeTS: Small: Towards Exposing and Mitigating End-to-End TCP Performance and Fairness Issues in Data Center Networks
-
批准号:1219004
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2012
-
负责人:Dongyan Xu
-
依托单位:
TC: EAGER: Binary-based Data Structure Revelation for Memory Forensics
-
批准号:1049303
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2010
-
负责人:Dongyan Xu
-
依托单位:
CSR-EHS: Collaborative Research: H-Media: The Holistic-Multistream Environment for Distributed Immersive Applicatons
-
批准号:0720665
-
项目类别:Continuing Grant
-
资助金额:$14.5万
-
财政年份:2007
-
负责人:Dongyan Xu
-
依托单位:
CT-ISG: Collaborative Proposal : Enabling Detection of Elusive Malware by Going Out of the Box with Semantically Reconstructed View (OBSERV)
-
批准号:0716444
-
项目类别:Standard Grant
-
资助金额:$13.0万
-
财政年份:2007
-
负责人:Dongyan Xu
-
依托单位:
CAREER: Towards Virtual Distributed Environments in a Shared Distributed Infrastructure
-
批准号:0546173
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2006
-
负责人:Dongyan Xu
-
依托单位:
SGER: Collaborative Research: NMI Development (CISE): Self-Managing Distributed Virtual Environments
-
批准号:0504261
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2005
-
负责人:Dongyan Xu
-
依托单位:
SCI: NMI DEPLOYMENT(ENG) nanoHUB
-
批准号:0438246
-
项目类别:Cooperative Agreement
-
资助金额:$0.0万
-
财政年份:2004
-
负责人:Dongyan Xu
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: