• KSII Transactions on Internet and Information Systems
    Monthly Online Journal (eISSN: 1976-7277)

Lightweight Intrusion Detection of Rootkit with VMI-Based Driver Separation Mechanism

Vol. 11, No. 3, March 30, 2017
10.3837/tiis.2017.03.026, Download Paper (Free):

Abstract

Intrusion detection techniques based on virtual machine introspection (VMI) provide high temper-resistance in comparison with traditional in-host anti-virus tools. However, the presence of semantic gap also leads to the performance and compatibility problems. In order to map raw bits of hardware to meaningful information of virtual machine, detailed knowledge of different guest OS is required. In this work, we present VDSM, a lightweight and general approach based on driver separation mechanism: divide semantic view reconstruction into online driver of view generation and offline driver of semantics extraction. We have developed a prototype of VDSM and used it to do intrusion detection on 13 operation systems. The evaluation results show VDSM is effective and practical with a small performance overhead.


Statistics

Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2015)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article

[IEEE Style]
C. Cui, Y. Wu, Y. Li, B. Sun, "Lightweight Intrusion Detection of Rootkit with VMI-Based Driver Separation Mechanism," KSII Transactions on Internet and Information Systems, vol. 11, no. 3, pp. 1722-1741, 2017. DOI: 10.3837/tiis.2017.03.026.

[ACM Style]
Chaoyuan Cui, Yun Wu, Yonggang Li, and Bingyu Sun. 2017. Lightweight Intrusion Detection of Rootkit with VMI-Based Driver Separation Mechanism. KSII Transactions on Internet and Information Systems, 11, 3, (2017), 1722-1741. DOI: 10.3837/tiis.2017.03.026.

[BibTeX Style]
@article{tiis:21409, title="Lightweight Intrusion Detection of Rootkit with VMI-Based Driver Separation Mechanism", author="Chaoyuan Cui and Yun Wu and Yonggang Li and Bingyu Sun and ", journal="KSII Transactions on Internet and Information Systems", DOI={10.3837/tiis.2017.03.026}, volume={11}, number={3}, year="2017", month={March}, pages={1722-1741}}