Title of article :
A guest-transparent file integrity monitoring method in virtualization
environment
Author/Authors :
Hai Jin ، نويسنده , , Guofu Xiang، نويسنده , , Deqing Zou، نويسنده , , Feng Zhao، نويسنده , , Min Li، نويسنده , , Chen Yu، نويسنده ,
Issue Information :
دوهفته نامه با شماره پیاپی سال 2010
Abstract :
The file system becomes the usual target of malicious attacks because it contains lots of
sensitive data, such as executable programs, configuration and authorization information.
File integrity monitoring is an effective approach to discover aggressive behavior by
detecting modification actions on these sensitive files. Traditional real-time integrity
monitoring tools, which insert hooks into the OS kernel, are easily controlled and disabled
by malicious software. Such existing methods, which insert kernel module into OS, are
hard to be compatible because of the diversity of OS. In this paper, we present a non-
intrusive real-time file integrity monitoring method in virtual machine-based computing
environment, which is transparent to the monitored system. The monitor is isolated from
the monitored system, since it observes the state of the monitored system from the outside.
This method brings two benefits: detecting file operations in real time and being invisible
to malicious attackers in the monitored system. Furthermore, a kind of file classification
algorithm based on file security level is proposed to improve efficiency in this paper. The
proposed file integrity monitoring method is implemented in the full-virtualization mode
supported by the Xen platform. The experimental results show that the method is effective
with acceptable overhead.
Keywords :
File integrity protection , Transparent monitoring , Real time , Xen
Journal title :
Computers and Mathematics with Applications
Journal title :
Computers and Mathematics with Applications