对于虚拟机监控器的动态完整性度量,由于其位于特权层,且复杂多变,一直是领域内的研究难点。提出了一种基于邻接点的动态完整性度量方法,利用邻接点作为度量模块的宿主,通过面向内存页的完整性模型和评估算法,实现了动态完整性度量。实验表明,能够准确地检测到完整性受到破坏,且仅对计算密集型任务造成适中的性能损耗。
Due to its high privilege and complicated runtime memory, dynamic integrity measurement for VMM(virtual machine monitor) was always a great difficulty in the current study. An innovative method based on the adjacency data was proposed, which used a neighbor as the host of a measurement module. According to an integrity model in memory page granularity and a new improved measurement algorithm, dynamic integrity measurement for VMM was implemented. Experimental data shows it could detect the integrity broken accurately, only causing a moderate performance loss for computing intensive tasks.