期刊导航

论文摘要

基于KVM的Windows客户机进程查杀技术

Online Anti-virus Technology of Processes Running on Windows VM Based on KVM

作者:崔竞松(武汉大学 计算机学院;武汉大学 空天信息安全与可信计算教育部重点实验室);向浩(武汉大学 计算机学院);郭迟(武汉大学 卫星定位导航技术研究中心);张雅娜(武汉大学 计算机学院);何松(武汉大学 计算机学院)

Author:Cui Jingsong(Computer School, Wuhan Univ.;Key Lab. of Aerospace Info. and Trusted Computing,Wuhan Univ.);Xiang Hao(Computer School, Wuhan Univ.);Guo Chi(Global Navigation Satellite System Research Center,Wuhan Univ.);Zhang Ya’na(Computer School, Wuhan Univ.);He Song(Computer School, Wuhan Univ.)

收稿日期:2014-06-23          年卷(期)页码:2014,46(6):7-13

期刊名称:工程科学与技术

Journal Name:Advanced Engineering Sciences

关键字:KVM虚拟化;虚拟化安全;无代理方式;进程监控;PE镜像还原;进程终止

Key words:KVM;virtualization security;agentless technique;process monitoring;PE image reduction;process killing

基金项目:国家高技术研究发展计划资助项目(2013AA12A206);国家自然科学基金资助项目(41104010;91120002;61170026)

中文摘要

传统反病毒架构不能有效利用虚拟化优势解决云平台上的Windows系统所面临的恶意软件威胁,并且传统反病毒软件自身面临安全威胁,针对此问题,提出一种基于KVM的无代理Windows客户机进程在线杀毒技术。通过在KVM内核模块中添加读写内存的函数,以及为进程处理模块提供在其中注册钩子的接口等方法,解析客户机当前进程信息。将进程在内存中的PE(portable executable)镜像大致还原成运行前的磁盘文件后,调用开源杀毒引擎ClamAV(Clam AntiVirus)进行扫描查毒。查毒结果返回给决策模块后,由进程处理内核模块对可疑进程进行相应处理,实现对客户机当前进程的无代理查杀。分析及测试结果表明,该技术利用虚拟化优势较好地解决了传统反病毒框架的资源耗费和自身安全性问题。

英文摘要

Aiming at the problem that the traditional anti-virus structure cannot effectively solve malware threats on Windows OS on virtualization platform by using the benefits of virtualization, and traditional anti-virus softwares have to face their own security threats, an agentless online anti-virus technology of processes running on Windows VM based on KVM was proposed. By adding memory reading and writing functions in KVM kernel module and providing interfaces to register hooks in the kernel module of processes handling, the VM’s processes’ information could be resolved. After restoring process’s PE image in memory into disk file before running, the open source antivirus engine ClamAV would be called to scan virus. When results returned to the decision-making module, process handling module would deal with suspicious processes accordingly, and the current process could be scanned and killed without any agent. Analysis and test results showed that the technique could solve the traditional anti-virus frameworks’ resource consumption and security issues by taking advantage of virtualization’s benefits.

关闭

Copyright © 2020四川大学期刊社 版权所有.

地址:成都市一环路南一段24号

邮编:610065