A virtualization-based approach for application whitelisting

科研成果: 期刊稿件文章同行评审

摘要

A whitelisting approach is a promising solution to prevent unwanted processes (e.g., malware) getting executed. However, previous solutions suffer from limitations in that: 1) Most methods place the whitelist information in the kernel space, which could be tempered by attackers; 2) Most methods cannot prevent the execution of kernel processes. In this paper, we present VAW, a novel application whitelisting system by using the virtualization technology. Our system is able to block the execution of unauthorized user and kernel processes. Compared with the previous solutions, our approach can achieve stronger security guarantees. The experiments show that VAW can deny the execution of unwanted processes effectively with a little performance overhead.

源语言英语
页(从-至)1648-1651
页数4
期刊IEICE Transactions on Information and Systems
E97-D
6
DOI
出版状态已出版 - 6月 2014

指纹

探究 'A virtualization-based approach for application whitelisting' 的科研主题。它们共同构成独一无二的指纹。

引用此