Towards Implicitly Introspecting the Preinstalled Operating System with Local-Booting Virtualization Technology

Yan Wen, Jinjing Zhao, Hua Chen, Minhuan Huang
{"title":"Towards Implicitly Introspecting the Preinstalled Operating System with Local-Booting Virtualization Technology","authors":"Yan Wen, Jinjing Zhao, Hua Chen, Minhuan Huang","doi":"10.1109/DASC.2013.34","DOIUrl":null,"url":null,"abstract":"The virtual machine (VM) based introspection on the operating system (OS) holds predominance over previous host-based introspectors for being more resistant to attack while suffering the difficulty of retrieving the semantic view of the OS. Previous approaches addressing this limitation highly depend on the explicit guest information which is still subvertable to the privileged malware. Moreover, they only deal with the OS deployed in the VM instead of our daily used native OS. In this paper, we present a new VM-based introspecting approach called Pisces which accurately reproduces the execution environment of the underlying preinstalled OS within the Pisces VM and provides an OS-level semantic view. With our novel local-booting virtualization technology, Pisces VM just boots from the underlying host OS but not a newly installed OS image. Thus, Pisces provides a feasible way to introspect on the existing OS. In addition, instead of relying on the explicit guest information, Pisces adopts a set of unique techniques to implicitly construct the semantic view of the OS from within the virtualized hardware layer. The evaluation results demonstrate its practicality and effectiveness.","PeriodicalId":179557,"journal":{"name":"2013 IEEE 11th International Conference on Dependable, Autonomic and Secure Computing","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-12-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 IEEE 11th International Conference on Dependable, Autonomic and Secure Computing","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/DASC.2013.34","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The virtual machine (VM) based introspection on the operating system (OS) holds predominance over previous host-based introspectors for being more resistant to attack while suffering the difficulty of retrieving the semantic view of the OS. Previous approaches addressing this limitation highly depend on the explicit guest information which is still subvertable to the privileged malware. Moreover, they only deal with the OS deployed in the VM instead of our daily used native OS. In this paper, we present a new VM-based introspecting approach called Pisces which accurately reproduces the execution environment of the underlying preinstalled OS within the Pisces VM and provides an OS-level semantic view. With our novel local-booting virtualization technology, Pisces VM just boots from the underlying host OS but not a newly installed OS image. Thus, Pisces provides a feasible way to introspect on the existing OS. In addition, instead of relying on the explicit guest information, Pisces adopts a set of unique techniques to implicitly construct the semantic view of the OS from within the virtualized hardware layer. The evaluation results demonstrate its practicality and effectiveness.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
用本地引导虚拟化技术实现预安装操作系统的隐式自省
在操作系统(OS)上基于虚拟机(VM)的自省比以前基于主机的自省具有优势,因为在检索操作系统的语义视图方面存在困难,但更能抵抗攻击。以前解决此限制的方法高度依赖于显式来宾信息,这些信息仍然可以被特权恶意软件颠覆。此外,它们只处理部署在VM中的操作系统,而不是我们日常使用的本机操作系统。在本文中,我们提出了一种新的基于虚拟机的自省方法,称为双鱼座,它准确地再现了双鱼座虚拟机中底层预装操作系统的执行环境,并提供了一个操作系统级别的语义视图。使用我们新颖的本地引导虚拟化技术,双鱼座VM只从底层主机操作系统启动,而不是从新安装的操作系统映像启动。因此,双鱼座提供了一种对现有操作系统进行内省的可行方法。此外,双鱼座采用了一套独特的技术,从虚拟硬件层内隐式地构建操作系统的语义视图,而不是依赖于显式的客户信息。评价结果表明了该方法的实用性和有效性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
An Improved Algorithm for Dynamic Cognitive Extraction Based on Fuzzy Rough Set An Improved Search Algorithm Based on Path Compression for Complex Network Dynamic Spectrum Sensing for Energy Harvesting Wireless Sensor Study and Application of Dynamic Collocation of Variable Weights Combination Forecasting Model A Multicast Routing Algorithm for GEO/LEO Satellite IP Networks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1