首页> 外文会议>Computer Security Applications Conference, 2009. ACSAC '09 >SHELF: Preserving Business Continuity and Availability in an Intrusion Recovery System
【24h】

SHELF: Preserving Business Continuity and Availability in an Intrusion Recovery System

机译:架子:在入侵恢复系统中保持业务连续性和可用性

获取原文
获取外文期刊封面目录资料

摘要

Recovering from intrusions for a compromised computer system is a challenging job, especially for systems that run continuous services. Current intrusion recovery techniques often do not preserve the accumulated useful state of running applications and have very limited system availability when performing recovery routines. In this paper, we propose SHELF, an on-the-fly intrusion recovery prototype system that provides a comprehensive solution to preserve business continuity, availability and recovery accuracy. SHELF preserves accumulated clean states for infected applications and files so that they can continue with the most recent pre-infection states after recovery. Moreover, SHELF leverages OS-aware taint tracking techniques to swiftly determine the sources of intrusion and assess system-wide damages caused by the intrusion. SHELF uses quarantine methods to prevent infection propagation so that uninfected and recovered objects can provide availability during the recovery phase. We integrate SHELF prototype in a virtualization environment to achieve user transparency and protection. Our evaluation shows that SHELF can perform accurate recovery on-the-fly effectively with an acceptable performance overhead.
机译:对于受到破坏的计算机系统,要从入侵中恢复是一项艰巨的任务,尤其是对于运行连续服务的系统而言。当前的入侵恢复技术通常无法保留正在运行的应用程序的累积有用状态,并且在执行恢复例程时具有非常有限的系统可用性。在本文中,我们提出了SHELF,这是一种即时的入侵恢复原型系统,它提供了一种全面的解决方案来保持业务连续性,可用性和恢复准确性。 SHELF会为受感染的应用程序和文件保留累积的干净状态,以便它们在恢复后可以继续使用最新的感染前状态。此外,SHELF利用OS感知的污点跟踪技术来快速确定入侵源并评估由入侵造成的系统范围的损害。 SHELF使用隔离方法来防止感染传播,以便未感染和已恢复的对象可以在恢复阶段提供可用性。我们将SHELF原型集成到虚拟化环境中,以实现用户透明性和保护。我们的评估表明,SHELF可以以可接受的性能开销有效地实时执行准确的恢复。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号