“In-VM”模型的隐藏代码检测模型

来源 :中国通信 | 被引量 : 0次 | 上传用户:simba_m
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Security tools are rapidly developed as network security threat is becoming more and more serious. To overcome the fundamental limitation of traditional host-based anti-malware system which is likely to be deceived and attacked by malicious codes, VMM-based anti-malware systems have re-cently become a hot research field. In this article, the existing malware hiding technique is analyzed, and a detecting model for hidden process based on “In-VM” idea is also proposed. Based on this detecting model, a hidden process detection tech-nology which is based on HOOK SwapContext on the VMM platform is also implemented successful-ly. This technology can guarantee the detecting method not to be attacked by malwares and also resist all the current process hiding technologies. In order to detect the malwares which use remote injection method to hide themselves, a method by hijacking sysenter instruction is also proposed. Ex-periments show that the proposed methods guar-antee the isolation of virtual machines, can detect all malware samples, and just bring little perform-ance loss.
其他文献
本文通过对荣华二采区10
期刊
请下载后查看,本文暂不支持在线获取查看简介。 Please download to view, this article does not support online access to view profile.
期刊
加拿大的商业电视台在黄金时段几乎全部播出美国电视节目,因为与美国广播网之间有合约规定,如果不播放这些节目的高清版本,就无法得到同步播放的权利,这在客观上促进了加拿大
请下载后查看,本文暂不支持在线获取查看简介。 Please download to view, this article does not support online access to view profile.
期刊
姜枫Jiang Feng陕西咸阳人。1986年考入西安美术学院国画系山水专业,师从山水画家徐义生、赵步唐先生,1990年毕业并获学士学位。现为咸阳画院专职画家,主攻山水。读姜枫的画,
目的 探究宫体注射欣母沛预防剖宫产产妇宫缩乏力产后出血的合理时机.方法 将60名行剖宫产且伴有宫缩乏力产后出血的产妇分为3组.第1组胎儿娩出后立即给予缩宫素静脉滴注,并
基于计算机测控技术与远程网络通信技术,设计了整套某型蒸气发电机组监测系统.并着重阐述了网络通信技术在系统软件设计中的应用,通过对网络通信协议、传输策略的选取以及开
期刊
用熔融法制备了Tb3+/Eu3+共掺的硼酸盐玻璃,研究了Tb3+、Eu3+共掺的硼酸盐玻璃的发光性能.结果表明,Tb3+/Eu3+共掺的硼酸盐玻璃的最强激发峰位于393 nm,最强发射峰是位于612
付费频道难,缺钱、缺人、缺内容、缺用户,而这几个关键要素又相互掣肘,迎难而上还是甘于低水平循环,是今天付费频道内容商的最大苦恼。民以食为天,数字电视的精神食粮是“内