Dissertation > Excellent graduate degree dissertation topics show

Hardware Virtualization Assisted Security Monitor for Cross-Platform Protection

Author: Zhu
Tutor: QiZhengWei
School: Shanghai Jiaotong University
Course: Software Engineering
Keywords: Hardware virtualization Cross-platform Security Memory self- transparent
CLC: TP309
Type: Master's thesis
Year: 2010
Downloads: 150
Quote: 2
Read: Download Dissertation

Abstract


Many operating systems are designed to manage and control system resources, they tend to have a large and complicated features, so they need a high level of security protection. The previous security applications in untrusted execution environment, so we can not provide adequate protection. And the different commercial operating system as well as the different open-source operating system, has its own design architecture and implementation methods, traditional security methods need to adapt to a different operating system. Deficiencies in the existing security protection, the issue is hardware virtualization technology to achieve a lightweight cross-platform system protection. Virtualization technology can make a high degree of isolation between the virtual machine and the operating environment of the monitoring layer, so even if the virtual machine is untrusted execution environment will not affect the operation of the monitoring program. Hypervisor and at a higher privilege level the relative virtual machine operating system, makes it possible to monitor the virtual machine is running, and the right to get more hardware resources. Whether malicious code running under the operating system which privilege level, monitoring procedures are able to detect as well as the power to stop them from running in the operating system to run programs are unable to detect the presence of the safety monitoring program. This paper presents a hardware-based virtualization and trusted execution environment hypervisor to monitor malicious behavior under a variety of operating systems, known as VASP. The platform is mainly reflected the three innovations advantages. First of all, the protection of the platform is a lightweight, low-overhead virtual machine monitoring platform. Use of code optimization to minimize the size of the virtual machine monitor, thereby reducing the volume of the trusted computing base, more safe and effective monitoring layer. And in the protection of the process to minimize the impact of the implementation of the operating system process, so that the monitoring overhead to a minimum. Secondly, the protection mechanisms implemented in this topic provides a cross-operating system platform support without having to modify the source code of the operating system, and in most conservation process. Match in the implementation process, VASP just need to call the lock mechanism as well as memory allocation mechanism based on the operating system API function to perform the rest of the code and operating system platforms. Thanks to the x86 hardware virtualization technology, making interception behavior by the completion of the CPU hardware, no software involved in the process of monitoring intercept. Finally, VASP protection platform can provide support for a variety of system protection, including I / O access protection, anti-debugging protection as well as memory access protection. And on this basis, through increased system functionality in the form of extensions to add more system protection mechanisms. Meanwhile, VASP to achieve self-protection mechanism, transparent memory technology. This mechanism can hypervisor can not be virtual machine operating system virtual memory access to discover the existence of its own. The papers topics designed to establish the safety monitoring program resides entirely on the outside of the operating system runtime environment with very little overhead. Can be proved through experiments based on hardware virtualization cross-platform security mechanisms to effectively prevent the infringement of certain malicious behavior, and can provide security protection for different operating system platforms, such as Windows XP and Fedora Linux, but only to reduce the tiny system overhead.

Related Dissertations

  1. Design and Implementation of Windows Kernel-mode Cryptographic Service Interface,TP309.7
  2. The Design and Implementation of Security Mechanism of Embedded Dependable Computer,TP309
  3. The Research of Vector CAD Electronic Drawing Protection System,TP391.72
  4. The Research of Malware Detection Technology Based on Active Mode,TP393.08
  5. Topology Measurement and Security Analysis on Gnutella and eMule Network,TP393.08
  6. Multiple Pairwise Keys Management Protocol of Function Node-Based for Wireless Sensor Networks,TP212.9
  7. Military exercises in the Corps of Engineers engineering equipment maintenance to protect the allocation of resources,E251.2
  8. Implementation and Research of Illegal Websites Detection System Based on Comparison Methods,TP393.08
  9. Study on US Veterans’ Social Security System and Its Enlightenment to China,E712
  10. Yellow phosphorus storage tank area of Safety Evaluation,TQ126.317
  11. The Study of Social Security System of the Fishermen of Guangdong after the Beibu Gulf Demarcation,F323.89
  12. Health protection of migrant workers,D412.6
  13. Research on Selection and Construction of the China’s Social Security Budget Pattern,D632.1
  14. Comprehensive Evaluation of Ecological Security of Land Application,X826
  15. Study on Evaluation Index System for Land Ecological Security,X826
  16. Urban Community Security Service Research in Terms of New Public Service Theory,D631.4
  17. Research on the Social Security of Fishermen under the Harmonious Society,D632.1
  18. Genetically Modified Food Ethics,B82-05
  19. On the systematic construction of the Chinese Communist Party democracy,D262.11
  20. The Analysis about Modes of Exchanging Land Contracted Management Right for Urban Social Security,D632.1
  21. Research on a Fire-fighting Shell for Towers,TU892

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > General issues > Security and confidentiality
© 2012 www.DissertationTopic.Net  Mobile