Automated Virtual Machine Introspection for Host-Based Intrusion Detection
| AUTHOR | Pagel, Brett A. |
| PUBLISHER | Biblioscholar (10/17/2012) |
| PRODUCT TYPE | Paperback (Paperback) |
Description
This thesis examines techniques to automate configuration of an intrusion detection system utilizing hardware-assisted virtualization. These techniques are used to detect the version of a running guest operating system, automatically configure version-specific operating system information needed by the introspection library, and to locate and monitor important operating system data structures. This research simplifies introspection library configuration and is a step toward operating system independent introspection. An operating system detection algorithm and Windows virtual machine system service dispatch table monitor are implemented using the Xen hypervisor and a modified version of the XenAccess library. All detection and monitoring is implemented from the Xen management domain.
Show More
Product Format
Product Details
ISBN-13:
9781249836421
ISBN-10:
1249836425
Binding:
Paperback or Softback (Trade Paperback (Us))
Content Language:
English
More Product Details
Page Count:
108
Carton Quantity:
41
Product Dimensions:
7.44 x 0.22 x 9.69 inches
Weight:
0.46 pound(s)
Feature Codes:
Illustrated
Country of Origin:
US
Subject Information
BISAC Categories
Education | General
Descriptions, Reviews, Etc.
publisher marketing
This thesis examines techniques to automate configuration of an intrusion detection system utilizing hardware-assisted virtualization. These techniques are used to detect the version of a running guest operating system, automatically configure version-specific operating system information needed by the introspection library, and to locate and monitor important operating system data structures. This research simplifies introspection library configuration and is a step toward operating system independent introspection. An operating system detection algorithm and Windows virtual machine system service dispatch table monitor are implemented using the Xen hypervisor and a modified version of the XenAccess library. All detection and monitoring is implemented from the Xen management domain.
Show More
Your Price
$68.82
