XIANG Guo-Fu
School of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, ChinaJIN Hai
School of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, ChinaZOU De-Qing
School of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, ChinaCHEN Xue-Guang
Department of Control Science and Engineering, Huazhong University of Science and Technology, Wuhan 430074, ChinaIn recent years, virtualization technology is the novel trendy of computer architecture, and it provides a solution for security monitoring. Due to the highest privilege and the smaller trusted computing base of virtual machine monitor, security tools, deployed in an isolated virtual machine, can inspect the target virtual machine with the help of virtual machine monitor. This approach can enhance the effectiveness and anti-attack ability of security tools. From the aspect of the implementation technologies, existing research works can be classified into internal monitoring and external monitoring. According to the different targets, the related works about virtualization-based monitoring are introduced in this paper in detail, such as intrusion detection, honeypot, file integrity monitoring, malware detection and analysis, security monitoring architecture and the generality of monitoring. Finally, this paper summarizes the shortcomings of existing works, and presents the future research directions. It is significant for virtualization research and security monitoring research.
项国富,金海,邹德清,陈学广.基于虚拟化的安全监控.软件学报,2012,23(8):2173-2187
Copy