Dissertation > Excellent graduate degree dissertation topics show

Research on Technique of BIOS Trojan Detection

Author: LiuJianFei
Tutor: XuMengChun
School: PLA Information Engineering University
Course: Software Engineering
Keywords: Hardware Virtualization Process Hiding Cross-view Process Detection VirtualMachine Monitor
CLC: TP309
Type: Master's thesis
Year: 2012
Downloads: 53
Quote: 0
Read: Download Dissertation

Abstract


With the rapid development of malicious programs, nowadays people pay more and moreattention to information security issues. Along with the mature of the technology of Rootkit, themalicious code has been hidden more deeply with the help of it. Because of the disadvantages ofthe detection technology of traditional process, such as lower access, backward detection meansand limited to users’ operating system, it can’t finish detecting to hidden process, creatingmonitoring, terminating,and so on effectively. Sometimes even itself will be attacked ordestroyed by malicious processes. The development of the technology of Virtualization hardwareprovides new ideas for the security software development.Cross-view comparison is a common method of detecting hidden processes. Its effectivenessdepends largely on the ability to obtain a credible process list. The existing cross-viewcomparison accesses information by setting information acquisition in the operating systems. It’seasy for the kernel-level Rootkit to cheat and bypass it. At the same time, the detection softwareitself can’t be guaranteed to get security. For this problem, For this problem, we designed andrealized the process detection system based on Virtual Hardware by building a light virtualmachine monitor. We monitor the Guest operating system fully by using the highest level ofprivilege of the Virtual Machine Monitor and collect credible information of the process onlineoutside the operating system to detect.Paper work and innovations include:1. Conduct a in-depth analysis and research of Hardware Virtualization Technologyespecially the Intel VT-x Technology. On the basis, this paper constructs a light VMM with theIntel VT-x technology.2. Through analysising of Hardware Virtualization and operating system kernel in-depth,combining with the existing communication mechanisms of operating system, and newinstructions of Hardware Virtualization, This paper proposes a semantic mapping and semanticreconstruction method to fill the semantic gap and to achieve effective communications betweenthe VMM and the Guest OS. On this basis, the detection of hidden process is realized.3. On the basis of traditional clearing memory method to terminate the process, take fulladvantage of the privilege advantage of the VMM, this paper puts forward a way to intercept theaction of MOV CR3in the VMM to identify the process to be terminated, and by traversing0-2G address space to accurately locate the memory space of the process to be terminated, andachieve the target process termination by memory reset.4. This paper creates a method to monitor the creation of the process by creating a blacklist and destroying the creation of malicious processes in VMM, and this way need’t hook anyfunction of the system, to ensure the integrity of the system.The test results show that the system can detect the hidden processes reliably, itsperformance overhead is small, with good usability.

Related Dissertations

  1. File Protection System Research Based on Hardware Assisted Virtualization,TP309
  2. Research on Rootkit Detection Technology Based on Hardware Virtualization Technology,TP393.08
  3. High hidden Trojan detection technology to achieve the depth of research,TP393.08
  4. The Research of Technology on Hidden Program Detection on Current Preferred Operating System,TP393.08
  5. The Research and Implementation of Trusted Execution Environment Based on Trusted Computing Platform,TP393.08
  6. Research on Rootkit Detection Based on the Analysis of Physical Memory and Realization,D918.2
  7. Hardware Virtualization Assisted Security Monitor for Cross-Platform Protection,TP309
  8. Study on the Automatic Check & Sub-selecting System for Detecting Bearing Rings of Missing Procedure,TH165.2
  9. Research on Nondestructive Detection Technology of Walnut Quality,TP274
  10. Research on LTE Downlink Synchronization Algorithm,TN929.5
  11. Research and Application on Process Measurement of Solid-State Fermentation (SSF) Based on Near-Infrared Spectroscopy (NIRS) and Electronic Nose Techniques,S816
  12. The Characteristic Research and Detection of Extreme Climate Events According to Probability Theory and Process Principle under the Bankground of Warming,P467
  13. Study on Application and Technology of Field-Flow Fractionation,TQ028
  14. Design and Implemetation of Host-Based Malcode Detection System,TP393.08
  15. Optimization of TFT-LCD Module Testing Process,TP274.4
  16. Design and Implementation of IP Flow Filter of Operational Duty System,TP311.52
  17. Trojan -based research network attacks,TP393.08
  18. Computer Crime Investigation mode,D918
  19. Study and Implementation on Process Detection Model and Correlative Technology,TP393.08
  20. SMART-VMM: The Design and Implementation of Virtual Machine Monitor Based on VT-x,TP302

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > General issues > Security and confidentiality
© 2012 www.DissertationTopic.Net  Mobile