Back to Search

Automated Virtual Machine Introspection for Host-Based Intrusion Detection

AUTHOR Pagel, Brett A.
PUBLISHER Biblioscholar (10/17/2012)
PRODUCT TYPE Paperback (Paperback)

Description
This thesis examines techniques to automate configuration of an intrusion detection system utilizing hardware-assisted virtualization. These techniques are used to detect the version of a running guest operating system, automatically configure version-specific operating system information needed by the introspection library, and to locate and monitor important operating system data structures. This research simplifies introspection library configuration and is a step toward operating system independent introspection. An operating system detection algorithm and Windows virtual machine system service dispatch table monitor are implemented using the Xen hypervisor and a modified version of the XenAccess library. All detection and monitoring is implemented from the Xen management domain.
Show More
Product Format
Product Details
ISBN-13: 9781249836421
ISBN-10: 1249836425
Binding: Paperback or Softback (Trade Paperback (Us))
Content Language: English
More Product Details
Page Count: 108
Carton Quantity: 41
Product Dimensions: 7.44 x 0.22 x 9.69 inches
Weight: 0.46 pound(s)
Feature Codes: Illustrated
Country of Origin: US
Subject Information
BISAC Categories
Education | General
Descriptions, Reviews, Etc.
publisher marketing
This thesis examines techniques to automate configuration of an intrusion detection system utilizing hardware-assisted virtualization. These techniques are used to detect the version of a running guest operating system, automatically configure version-specific operating system information needed by the introspection library, and to locate and monitor important operating system data structures. This research simplifies introspection library configuration and is a step toward operating system independent introspection. An operating system detection algorithm and Windows virtual machine system service dispatch table monitor are implemented using the Xen hypervisor and a modified version of the XenAccess library. All detection and monitoring is implemented from the Xen management domain.
Show More
Your Price  $68.82
Paperback