Provided is a magnetic disc file operation
monitoring system based on Xen hardware
full virtualization. The magnetic disc file operation
monitoring system comprises a supervision module, an information sending module, a monitoring module and a safety module. The supervision module obtains behavior information through interception of magnetic disc file operations of a full-
virtualization user operation
system so as to achieve the purpose of supervision. The information sending module and the monitoring module enable the behavior information to be transmitted from a domU to a domO. The safety module guarantees
operation safety of the information sending module and the monitoring module. The invention provides a monitoring method which includes the steps of intercepting and replacing call of the magnetic disc file operation
system in
full virtualization, determining types of monitored files, determining whether the files need to be monitored in the operation process, comprehensively determining whether a behavior needs to be monitored according to operation types, the file types and
process information, obtaining the behavior information, obtaining an operation target absolute path, sending information, performing
information monitoring, and detecting whether the supervision module and the information sending module are attacked when codes are operated, wherein the supervision module and the information sending module are operated under the domU. According to the magnetic disc file operation
monitoring system and the monitoring method based on Xen
hardware virtualization, real-time monitoring is achieved, and I / O efficiency of an Xen full-
virtualization network is improved.