Getting process content of guest OS based on VMI

Yong-gang LI,Chao-yuan CUI,Ping LI
DOI: https://doi.org/10.16208/j.issn1000-7024.2016.06.051
2016-01-01
Abstract:Aiming at the problem of the present situation that it is difficult to get the process content of guest OS out of virtual machine and there exists semantic gap between virtual vachines,a technology for obtaining the process content in virtual machine operating system was put forward.On the Xen virtualization platform,the technology started with virtual CPU context informa-tion,and got the process content in memory page by page.The specific data structure was analyzed to acquire the underlying in-formation in memory.The technology can get a list of processes as well as the process code,map files and all other process’s un-derlying information of the guest OS out of virtual machine.The process content gained can provide a foundation for the study of process at granularity.
What problem does this paper attempt to address?