Full-virtualization-based Process Monitoring Method

杜海,陈榕
DOI: https://doi.org/10.3969/j.issn.1000-3428.2009.08.030
2009-01-01
Abstract:Aiming at the problems existed in Operating System(OS) process monitoring, a new full-virtualization-based process monitoring method is proposed. It uses full virtualization technology to detect and isolate all the harmful behaviors of untrusted processes in OS. Experimental results show this method has better performances of pellucidity and portability, which can prevent against multiple attacks and incur only a small amount of performance overhead.
What problem does this paper attempt to address?