• DocumentCode
    1960552
  • Title

    SecMon: A Secure Introspection Framework for Hardware Virtualization

  • Author

    Xiaolong Wu ; Yunwei Gao ; Xinhui Tian ; Ying Song ; Bing Guo ; Baiming Feng ; Yuzhong Sun

  • Author_Institution
    Coll. of Comput. Sci., Sichuan Univ., Chengdu, China
  • fYear
    2013
  • fDate
    Feb. 27 2013-March 1 2013
  • Firstpage
    282
  • Lastpage
    286
  • Abstract
    With the fusion of cloud computing and virtualization technology, system security under virtualization becomes a key point in recent research. As a foundational technology to construct a secure system, virtual machine introspection receives more attention than ever. Almost all of the existing virtual machine monitors take the privileged virtual machine (Domain-0) as the monitoring machine, which ignore the threats brought by Domain-0 because of its huge code base of user-level tools. Besides, para-virtualized machines cannot provide the basic support for popular security applications of Windows operating system. This paper proposes a secure monitoring framework based on hardware virtualization. We use Windows operating system to build a monitoring virtual machine in hardware virtual machine domain, and set up monitoring mechanism in it. In addition, the security of the Windows monitoring machine itself is ensured all through its lifetime-bootstrap and runtime. The experiments show our secure monitoring system performs well in the secure monitoring process. The performance overhead it brings is considered to be acceptable.
  • Keywords
    cloud computing; computer bootstrapping; computerised monitoring; operating systems (computers); user interfaces; virtual machines; virtualisation; Domain-0; SecMon; Windows monitoring machine; Windows operating system; cloud computing; hardware virtualization-based secure monitoring framework; paravirtualized machines; secure introspection framework; secure system; system security; user-level tools; virtual machine monitoring; Hardware; Monitoring; Operating systems; Runtime; Security; Virtual machining; Virtualization; cloud computing; hardware virtual machine; static metrics; virtual machine introspection; virtualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel, Distributed and Network-Based Processing (PDP), 2013 21st Euromicro International Conference on
  • Conference_Location
    Belfast
  • ISSN
    1066-6192
  • Print_ISBN
    978-1-4673-5321-2
  • Electronic_ISBN
    1066-6192
  • Type

    conf

  • DOI
    10.1109/PDP.2013.48
  • Filename
    6498565