ZHANG Lei, CHEN Xing-shu, LIU Liang, LI Hui. A Kernel Integrity Protection Technology Based on Virtual Machine[J]. Journal of University of Electronic Science and Technology of China, 2015, 44(1): 117-122. DOI: 10.3969/j.issn.1001-0548.2015.01.020
Citation: ZHANG Lei, CHEN Xing-shu, LIU Liang, LI Hui. A Kernel Integrity Protection Technology Based on Virtual Machine[J]. Journal of University of Electronic Science and Technology of China, 2015, 44(1): 117-122. DOI: 10.3969/j.issn.1001-0548.2015.01.020

A Kernel Integrity Protection Technology Based on Virtual Machine

  • For the kernel integrity threats of virtual machine in cloud computing environment, an integrity protecting technology of virtual machine kernel, cloud trusted virtual machine(CTVM), is proposed. In the CTVM, the virtual trusted execution environment in kernel-based virtual machine(KVM) is created, the multiple virtual machines are endowed with a trusted computing function at the same time, and the guest virtual machines are provided with integrity measurement ability. By utilizing hardware virtualization technology, the untrusted kernel modules are isolated from operating system kernel through constructing isolated address space in guest virtual machines, so as to protect the booting integrity and runtime integrity of guest virtual machines. Finally, with a domestic server as the experimental platform, CTVM prototype system is presented. System test and analysis show that the system performance loss is within the acceptable range.
  • loading

Catalog

    /

    DownLoad:  Full-Size Img  PowerPoint
    Return
    Return