articleJan 1, 2003Closed access

A Virtual Machine Introspection Based Architecture for Intrusion Detection.

Stanford University

Abstract

Today's architectures for intrusion detection force the IDS designer to make a difficult choice. If the IDS resides on the host, it has an excellent view of what is happening in that host's software, but is highly susceptible to attack. On the other hand, if the IDS resides in the network, it is more resistant to attack, but has a poor view of what is happening inside the host, making it more susceptible to evasion. In this paper we present an architecture that retains the visibility of a host-based IDS, but pulls the IDS outside of the host for greater attack resistance. We achieve this through the use of a virtual machine monitor. Using this approach allows us to isolate the IDS from the…

Citation impact

1,322
total citations
FWCI
20.12
Percentile
100%
References
26
Citations per year

Authors

2

Topics & keywords

Keywords
  • Host (biology)
  • Intrusion detection system
  • Computer science
  • Evasion (ethics)
  • Visibility
  • Architecture
  • Software
  • Virtual machine
No related works found for this paper.