为缺乏详细说明在优先的工作语义,一种透明有细密纹理的监视技术(cMonitor ) 被建议。在外面部署了虚拟机, cMonitor 利用虚拟机监视器的提高的特权由重建在保护的系统监视在他们之间的网络连接,这些进程和关系有细密纹理的系统语义。这些语义包含过程状态和相应网络连接。试验性的结果显示出那 cMonitor 能很快不仅在现实主义的云被部署,而且能有效地并且普遍获得这些帮助一些的察觉的有细密纹理的语义进展了网络攻击。同时,网络表演开销是大约 3% ,它是可接受的。
For the lack of detailed semantic in prior works, a transparent fine-grained monitoring technique (cMonitor) is pro- posed. Deployed outside the virtual machines, the cMonitor util- izes the elevated privileges of the virtual machine monitor to monitor the network connection, the processes and the relationship between them in protected systems by reconstructing fine-grained system semantics. These semantics contain process states and corresponding network connection. Experimental results show that cMonitor not only can be rapidly deployed in realistic cloud, but also can effectively and universally obtain these fine-grained semantics to assist detection of some advanced network attack. Meanwhile, the network performance overhead is about 3%, which is acceptable.