The present application belongs to the technical field of computer
information security, and particularly relates to a cloud host security baseline checking method and
system based on
virtual machine introspection, which comprises the following steps: accessing a target
virtual machine through a host
virtualization management program layer and dividing physical memory pages, obtaining physical memory
dirty page states and
system I / O load; according to the
dirty page states of the physical memory pages in a historical observation window and a physical neighborhood set, obtaining an activity accumulation index and a spatial neighborhood linkage index at the
current time, respectively; obtaining a checking trigger
score according to the activity accumulation index, the spatial neighborhood linkage index and the
system I / O load, and realizing security baseline checking based on the threshold relationship of the checking trigger
score. The present application can identify normal business hotspots and abnormal tampering behaviors, and reduce the checking frequency when the system is under
high load, thereby realizing low-overhead agentless security baseline checking.