Multilevel Introspection of Nested Virtual Machines

作者: Dan H. Lutas , Raul V. Tosa , Sandor Lukacs

DOI:

关键词: HypervisorFull virtualizationComputer scienceHardware virtualizationVirtual machineStorage hypervisorVirtualizationEvent (computing)Operating systemHost (network)

摘要: Described systems and methods allow software introspection and/or anti-malware operations in a hardware virtualization system comprising nested hierarchy of hypervisors virtual machines, wherein is carried out to any level the from central location on host hypervisor. An engine intercepts processor event occurring machine exposed by hypervisor, determine an address object executing respective machine. The progressively translated down through all levels hierarchy, within memory space controlled Anti-malware procedures can thus be performed may comprise techniques such as signature matching protecting certain areas

参考文章(12)
Weidong Cui, Marcus Peinado, Martim Carbone, Data access reporting platform for secure active monitoring ,(2011)
Bich Cau Le, Yufeng Zheng, Derek Uluski, Xiaoxin Chen, Jagannath Gopal Krishnan, On-Access Anti-Virus Mechanism for Virtual Machine Architecture ,(2007)
Ben-Ami Yassour, Shmuel Ben-Yehuda, Nadav Yosef Har'El, Abel Gordon, Multilevel support in a nested virtualization environment ,(2011)
Randy A. Rendahl, Andrzej Kochut, Hidayatullah H. Shaikh, Alexei Karve, Anca Sailer, Yu Deng, Alla Segal, Co-location of virtual machines with nested virtualization ,(2012)
Prakash Linga, Phanindra V. R. Ganti, Constantine P. Sapuntzakis, Burt A. Toma, Robert A. Iannucci, Providing security for a virtual machine by selectively triggering a host security scan ,(2010)
Horacio Andres Lagar-Cavilla, Alexander Varshavsky, Remote-Assisted Malware Detection ,(2011)
Oded Horovitz, Dmitriy Budko, Carl A. Waldspurger, Xiaoxin Chen, Impeding progress of malicious guest software ,(2008)