发新话题
打印

[转载]Automated Defense From Rootkit Attacks

[转载]Automated Defense From Rootkit Attacks

信息来源:邪恶八进制信息安全团队(www.eviloctal.com

The growing popularity of virtualization has led companies to embrace virtual machines to host web services. Virtualized environment faces the same security problems as a machine running the standalone operating system. The virtualized environment, however, provides a stronger security model and certain properties of isolation and interposition that makes automated monitoring and healing a tractable problem. In this paper, we look at the rootkit attacks, which hide the compromised system from being detected. This type of attack is very hard to detect and recover from as it directly interferes with system integrity. Leveraging the virtual machine technology, we propose a novel solution to detect and contain the effects of a rootkit attack in virtual machines running commodity operating systems. We have developed a prototype for a Linux virtual machine using VMware Workstation to illustrate the concept. We also propose an extension to the design, which can perform automated fingerprinting of the attacks by tracking simple changes to the filesystem.

附件

Automated Defense From Rootkit Attacks.rar (158 KB)

2006-3-30 02:57, 下载次数: 85

曾几何时,有人对我说:装B遭雷劈。我说:去你妈的。于是,这个人又对我说:如果再说脏话,上帝会惩罚你的。我说:我操上帝。结论:彪悍的人生不需要上帝。

TOP

发新话题