论文部分内容阅读
恶意软件对主机安全工具的威胁促使我们考虑借助虚拟化技术来提升安全系统的权限.本文提出了一种检测和阻止恶意软件伪装成合法程序发送非法数据流的方法,并基于虚拟机自省技术建立了安全框架,实现了以下三个方面的功能:首先,模型提供了对主机应用程序与用户交互的安全监控,通过对用户真正意图的捕捉与分析,检测和阻止被恶意软件伪装离开主机的网络数据流;其次,通过对虚拟机自省和内存分析技术的应用,并基于用户输入事件,保证了对程序预测行为的精确判断;最后,通过系统实现证实了模型对Windows下IE浏览器应用程序的兼容性.
Malware threats to the host security tools prompted us to consider the use of virtualization technology to enhance the security system permissions.This paper presents a method to detect and prevent malware disguised as legitimate programs to send illegal data streams and based on the virtual machine introspection technology The security framework implements the following three functions: First, the model provides security monitoring of the host application and user interaction. By capturing and analyzing users’ true intentions, the network detects and prevents the network disguised by the malware from leaving the host Data flow; Secondly, through the application of virtual machine introspection and memory analysis technology, and based on user input events, to ensure that the program predicts the behavior of accurate judgments; Finally, the system confirmed that the model of the IE browser applications under Windows compatibility.