Skip to main navigation Skip to search Skip to main content

Vmscan: An out-of-vm malware scanner

  • Lin Jie
  • , Liu Chuanyi*
  • , Fang Binxing
  • *Corresponding author for this work
  • School of Computer Science and Technology, Harbin Institute of Technology
  • Beijing University of Posts and Telecommunications
  • China Academy of Engineering Physics

Research output: Contribution to journalArticlepeer-review

Abstract

The harm caused by malware in cloud computing environment is more and more serious. Traditional anti-virus software is in danger of being attacked when it is deployed in virtual machine on a large scale, and it tends not to be accepted by tenants in terms of performance. In this paper, a method of scanning malicious programs outside the virtual machine is proposed, and the prototype is implemented. This method transforms the memory of the virtual machine to the host machine so that the latter can access it. The user space and kernel space of virtual machine memory are analyzed via semantics, and suspicious processes are scanned by signature database. Experimental results show that malicious programs can be effectively scanned outside the virtual machine, and the performance impact on the virtual machine is low, meeting the needs of tenants.

Original languageEnglish
Pages (from-to)59-68
Number of pages10
JournalJournal of China Universities of Posts and Telecommunications
Volume27
Issue number4
DOIs
StatePublished - Aug 2020
Externally publishedYes

Keywords

  • Cloud
  • Detection
  • Malware
  • Scanning
  • Security
  • Signature
  • Virtualization
  • Virus

Fingerprint

Dive into the research topics of 'Vmscan: An out-of-vm malware scanner'. Together they form a unique fingerprint.

Cite this