Journal on Communications ›› 2015, Vol. 36 ›› Issue (8): 31-37.doi: 10.11959/j.issn.1000-436x.2015103

• Academic paper • Previous Articles     Next Articles

Narrowing the semantic gap in virtual machine introspection

Chao-yuan CUI1,Yun WU2,Ping LI1,3,Xiao-ming ZHANG1   

  1. 1 Institute of Intelligent Machines,CAS,Hefei 230031,China
    2 Anhui Technology and Engineering Institute for Recycling Economy,CAS,Hefei 230088,China
    3 Department of Automation,University of Science and Technology of China,Hefei 230027,China
  • Online:2015-08-25 Published:2015-08-25
  • Supported by:
    Foundation of President of Hefei Institutes of Physical Science,Chinese Academy of Sciences;The National Natural Science Foundation of China;The National Natural Science Foundation of China

Abstract:

Virtual machine introspection(VMI)has been widely used in areas such as intrusion detection and malware analysis.However,due to the existence of semantic gap,the generality and the efficiency of VMI were partly influenced while getting internal information of a virtual machine.By analyzing the deficiencies of existing technology of semantic gap restoration,a method called ModSG was proposed to bridge the semantic gap.ModSG was a modularity system,it divided semantic restoration into two parts.One was online phase that interact directly with user to construct semantic views,the other was offline phase that only interact with operating system to parse high-level semantic knowledge.Both were implemented via independent module,and the latter provided the former with necessary kernel information during semantic view construction.Experiments on different virtual machine states and different kernel versions show that the ModSG is accurate and efficient in narrowing semantic gap.The modular design and deployment also make ModSG easily to be extended to other operating systems and virtualization platforms.

Key words: semantic gap, virtual machine introspection, modularity system, portability

No Suggested Reading articles found!