Title :
Virtual machine introspection based spurious process detection in virtualized cloud computing environment
Author :
Kumara, M. A. Ajay ; Jaidhar, C.D.
Author_Institution :
Dept. of Inf. Technol., Nat. Inst. of Technol., Mangalore, India
Abstract :
Virtual Machines are prime target for adversary to take control by exploiting the identified vulnerability present in it. Due to increasing number of Advanced Persistent Attacks such as malware, rootkit, spyware etc., virtual machine protection is highly challenging task. The key element of Advanced Persistent Threat is rootkit that provides stealthy control of underlining Operating System (kernel). Protecting individual guest operating system by using antivirus and commercial security defense mechanism is cost effective and ineffective for virtualized environment. To solve this problem, Virtual Machine Introspection has emerged as one of the promising approaches to secure the state of the virtual machine. Virtual Machine Introspection inspects the state of multiple virtual machines by operating outside the virtual machine i.e. at hypervisor level. In this work, Virtual Machine Introspection based malicious process detection approach is proposed. It extracts the high level information such as system call details, opened known backdoor ports from introspected memory to identify the spurious process. It triggers an alert in response to detected intrusion.
Keywords :
cloud computing; invasive software; operating system kernels; virtual machines; virtualisation; advanced persistent attacks; advanced persistent threat; antivirus; backdoor port; guest operating system protection; high level information; hypervisor level; intrusion detection; malicious process detection approach; malware; memory introspection; rootkit; security defense mechanism; spurious process detection; spyware; state inspection; stealthy control; system call details; underlining operating system kernel; virtual machine introspection; virtual machine protection; virtual machine state security; virtualized cloud computing environment; vulnerability exploitation; Kernel; Malware; Monitoring; Ports (Computers); Virtual machine monitors; Virtual machining; Hypervisor; Rootkit; Semantic Gap; Virtual Machine; Virtual Machine Introspection; Virtualization;
Conference_Titel :
Futuristic Trends on Computational Analysis and Knowledge Management (ABLAZE), 2015 International Conference on
Conference_Location :
Noida
Print_ISBN :
978-1-4799-8432-9
DOI :
10.1109/ABLAZE.2015.7155003