首页    期刊浏览 2024年07月09日 星期二
登录注册

文章基本信息

  • 标题:Incident-driven memory snapshot for full-virtualized OS using interruptive debugging techniques
  • 本地全文:下载
  • 作者:Ruo Ando ; Youki Kadobayashi ; Youichi Shinoda
  • 期刊名称:International Journal of Security and Its Applications
  • 印刷版ISSN:1738-9976
  • 出版年度:2008
  • 卷号:2
  • 期号:3
  • 出版社:SERSC
  • 摘要:Memory forensics is growing concern. For effective evidence retrieval, it is important to take snapshot timely. With proper modification of guest OS, VMM is powerful tool for timely snapshot. In this paper, we propose an incident-driven memory snapshot for full-virtualized OS using interruptive debugging techniques. We modify debug register handler to invoke snapshot facility of VMM. Software interrupt or signal are generated in register handler. Then, we can take snapshot asynchronously when debug register is changed. On guest OS, we apply three kinds of interruptive debugging techniques: driver supplied callback function, DLL injection. IDT (interruption descriptor table) is modified by driver supplied callback function, which makes it possible to cope with vulnerability exploitation. DLL injection is applied to insert security check function into a resource access function. Proposed system is implemented XEN virtual machine monitor and KVM (Kernel Virtual machine).
国家哲学社会科学文献中心版权所有