Dissertation > Excellent graduate degree dissertation topics show
Linux Kernel Module Rootkit Detection Based on System Virtual Machine Technology
Author: LiZuo
Tutor: DingYuXin
School: Harbin Institute of Technology
Course: Computer Science and Technology
Keywords: Cloud Computing Virtual machine technology Rootkit detection
CLC: TP391.3
Type: Master's thesis
Year: 2010
Downloads: 156
Quote: 0
Read: Download Dissertation
Abstract
|
Kernel mode rootkits malicious code hidden the best, the most difficult to detect malicious code. With the rapid development of cloud computing services, kernel mode rootkits have become a significant threat to the cloud. How to ensure data security in the cloud computing environment, malicious code detection in a virtualization environment using virtual machine technology has become the focus of the study. This paper mainly state Rootkit detection kernel-based virtual machine technology. This paper first introduces the principle of rootkit attacks and its detection technology were introduced. Kernel mode rootkit attack principle first in-depth analysis, and combined the LKM mechanisms and found that the most important characteristics of the kernel mode rootkit kernel critical data changes and hide itself and related malware. Then introduce the main detection techniques: traditional detection methods and virtual machine-based detection methods for these characteristics. Traditional detection methods for the detection of the the key kernel mode rootkit tampering kernel data. To detect hidden information characteristics for kernel mode rootkit detection methods are mainly based on the virtual machine. The traditional method for Rootkit detection for the static characteristics of its signature detection, better detection for user mode rootkits, but the results are not satisfactory Rootkit detection kernel mode. The topic for the kernel mode Rootkit hidden module characteristics, proposed a kernel mode rootkit detection method based on system virtualization technology. The method uses hardware virtualization VT-x technology and virtual machine as the technology to build the virtual machine view of the target client, and by intercepted the client module load removed, such as system calls to view up-to-date, by contrast in the module is loaded before and after view of the virtual machine and the target client build client view, and found differences in order to find the module may be hidden, and that the presence of the rootkit. Finally, we will be the system with the original Xen system performance comparison analysis of the reasons for performance degradation. The experimental results show that the cross-validation method not only to achieve the kernel mode Rootkit efficient detection and lower resource consumption. The topic also provides for the dynamic behavior of malicious code based on a virtual machine detection reference.
|
Related Dissertations
- The Research of Dynamic Trust Model on Cloud Computing Platform,TP309
- Research of Key Technologies Constructing Enterprise Information Systems Based on Cloud Computing,TP315
- Load Balance Approach to Save Power on Cloud Datacenter,TP308
- Logically oriented virtual domain multi -level access control system,TP309
- Fault Tolerance for MapReduce in the Cloud Environment,TP302.8
- Cloud-based Software Testing Services Research,TP311.53
- Cloud-based Scientific Workflow Data Storage Strategy,TP333
- Research on Rootkit Detection Technology Based on Hardware Virtualization Technology,TP393.08
- Data Privacy-Preserving Schemes for Cloud Computing,TP393.08
- Web application system design based on Google's cloud computing platform and,TP393.09
- Virus Detection Technology Based on Artificial Immune,TP393.08
- The Research of Software Service Platform Based on Cloud Computing,TP311.52
- The Operation and Maintenance of ITIL Based on Cloud Computing,TP311.52
- Design and Implementation based the Google platform promotional modules commodity module,TP311.52
- Research and Implementation on Model of Educational Knowledge Service System Based on Eucalyptus,TP393.09
- Research on Information Service Based on Cloud Computing,G252
- The Collection of Mobile Community Geographic Information,P208
- Research of Scheduling Technique in Telecom Business Supporting Based on Cloud Computing Platform,TN915.09
- Research and Design of Car GPS Navigation Terminal Based on Cloud Computing,TP3
- Reseach of Hadoop Cluster Based on Eucalyptus Cloud Platform,TP338.8
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Information processing (information processing) > Retrieval machine
© 2012 www.DissertationTopic.Net Mobile
|