TY - JOUR
T1 - A virtualization-based approach for application whitelisting
AU - Tian, Donghai
AU - Xue, Jingfeng
AU - Hu, Changzhen
AU - Li, Xuanya
PY - 2014/6
Y1 - 2014/6
N2 - A whitelisting approach is a promising solution to prevent unwanted processes (e.g., malware) getting executed. However, previous solutions suffer from limitations in that: 1) Most methods place the whitelist information in the kernel space, which could be tempered by attackers; 2) Most methods cannot prevent the execution of kernel processes. In this paper, we present VAW, a novel application whitelisting system by using the virtualization technology. Our system is able to block the execution of unauthorized user and kernel processes. Compared with the previous solutions, our approach can achieve stronger security guarantees. The experiments show that VAW can deny the execution of unwanted processes effectively with a little performance overhead.
AB - A whitelisting approach is a promising solution to prevent unwanted processes (e.g., malware) getting executed. However, previous solutions suffer from limitations in that: 1) Most methods place the whitelist information in the kernel space, which could be tempered by attackers; 2) Most methods cannot prevent the execution of kernel processes. In this paper, we present VAW, a novel application whitelisting system by using the virtualization technology. Our system is able to block the execution of unauthorized user and kernel processes. Compared with the previous solutions, our approach can achieve stronger security guarantees. The experiments show that VAW can deny the execution of unwanted processes effectively with a little performance overhead.
KW - Virtualization technology
KW - Whitelisting
UR - http://www.scopus.com/inward/record.url?scp=84901758672&partnerID=8YFLogxK
U2 - 10.1587/transinf.E97.D.1648
DO - 10.1587/transinf.E97.D.1648
M3 - Article
AN - SCOPUS:84901758672
SN - 0916-8532
VL - E97-D
SP - 1648
EP - 1651
JO - IEICE Transactions on Information and Systems
JF - IEICE Transactions on Information and Systems
IS - 6
ER -