Netinfo Security ›› 2016, Vol. 16 ›› Issue (9): 139-144.doi: 10.3969/j.issn.1671-1122.2016.09.028

• Orginal Article • Previous Articles     Next Articles

Research and Design on Abnormal Behavior Online Detection Platform Based on Xen

Pengfei NIU1, Jian ZHANG1(), Qing CHANG2, Zhaojun GU3   

  1. 1. School of Computer and Communication Engineering, Tianjin University of Technology, Tianjin 300384, China
    2. Department of Population Management, Tianjin Municipal Police Bureau, Tianjin 300161, China
    3. Information Security Evaluation Center of Civil Aviation, Civil Aviation University of China, Tianjin 300300, China
  • Received:2016-07-25 Online:2016-09-20 Published:2020-05-13

Abstract:

The traditional detection mechanism mainly based on the physical machine. The detection software is disturbed by the malicious software which resides on the same OS, so it is hard to detect OS status accurately. This paper presented an approach of supervision to the Internet by establishing an online detection platform against the abnormal behavior. It analyzed the key technologies in establishing the online detection platform and the characteristics of virtualization technology and virtual machine introspection technology. This paper proposes a method that can test and monitor the abnormal behavior in a continuous way relying on virtualization technology and virtual machine introspection technology. At last, this paper designs and implements a model of Xen-based online detection platform against the abnormal behavior.

Key words: abnormal behavior, virtualization technology, VMI, Xen, online detection

CLC Number: