首页> 外文会议>International conference on information security practice and experience >Design and Implementation of a Lightweight Kernel-Level Network Intrusion Prevention System for Virtualized Environment (Short Paper)
【24h】

Design and Implementation of a Lightweight Kernel-Level Network Intrusion Prevention System for Virtualized Environment (Short Paper)

机译:虚拟环境的轻量级内核级网络入侵防御系统的设计与实现(论文)

获取原文
获取外文期刊封面目录资料

摘要

Cloud platforms often take advantage of virtualization technology and make their actual hosts virtualized. As network attack events occur frequently, providing system security in a virtualized environment is the focus of this study. We have designed and implemented a lightweight network-based intrusion prevention system (IPS) named VMM-IPS for the virtual machine (VM) execution environment. To ensure the system safety of VMs and the host system at the same time, VMM-IPS is operated in the Linux kernel of the host system and co-located with the Kernel-based Virtual Machine that turns Linux kernel into a hypervisor. As packets enter the system, no matter destined to VMs or passing through the host, they are detected by VMM-IPS. Unlike user-level IPS that needs switching protection domain and copying packets to user buffer for inspection, VMM-IPS is more efficient because of the capability to perform in-place packet inspection. It adopts signature-based detection and is implemented with the multiple-pattern search algorithm AC-BM for efficient string matching. Besides, VMM-IPS can protect the system against attacks using packet splitting and reassembly to evade introduction detection system (IDS). The experimental results demonstrate VMM-IPS can achieve system safety effectively and efficiently.
机译:云平台通常利用虚拟化技术,并将其实际主机虚拟化。由于网络攻击事件频繁发生,因此在虚拟化环境中提供系统安全性是本研究的重点。我们已经为虚拟机(VM)执行环境设计并实现了一个名为VMM-IPS的基于网络的轻量级入侵防御系统(IPS)。为了同时确保VM和主机系统的系统安全性,VMM-IPS在主机系统的Linux内核中运行,并与基于内核的虚拟机位于同一位置,后者将Linux内核转变为虚拟机监控程序。当数据包进入系统时,无论是发往VM还是通过主机,VMM-IPS都会检测到它们。与需要切换保护域并将数据包复制到用户缓冲区以进行检查的用户级IPS不同,VMM-IPS具有执行就地数据包检查的功能,因此效率更高。它采用基于签名的检测,并使用多模式搜索算法AC-BM进行实现,以实现高效的字符串匹配。此外,VMM-IPS可以使用数据包拆分和重组来躲避引入检测系统(IDS),从而保护系统免受攻击。实验结果表明,VMM-IPS可以有效,高效地实现系统安全。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号