A virtualization-based approach for application whitelisting

Research output: Contribution to journalArticlepeer-review

Abstract

A whitelisting approach is a promising solution to prevent unwanted processes (e.g., malware) getting executed. However, previous solutions suffer from limitations in that: 1) Most methods place the whitelist information in the kernel space, which could be tempered by attackers; 2) Most methods cannot prevent the execution of kernel processes. In this paper, we present VAW, a novel application whitelisting system by using the virtualization technology. Our system is able to block the execution of unauthorized user and kernel processes. Compared with the previous solutions, our approach can achieve stronger security guarantees. The experiments show that VAW can deny the execution of unwanted processes effectively with a little performance overhead.

Original languageEnglish
Pages (from-to)1648-1651
Number of pages4
JournalIEICE Transactions on Information and Systems
VolumeE97-D
Issue number6
DOIs
Publication statusPublished - Jun 2014

Keywords

  • Virtualization technology
  • Whitelisting

Fingerprint

Dive into the research topics of 'A virtualization-based approach for application whitelisting'. Together they form a unique fingerprint.

Cite this