【24h】

VMFence

机译:VMFence

获取原文

摘要

Intrusion Prevention System (IPS) has been an effective tool to detect and prevent unwanted attempts, which are mainly through network and system vulnerabilities, at accessing and manipulating computer systems. Intrusion detection and prevention are two main functions of IPS. As attacks are becoming massive and complex, the traditional centralized IPSes are incapable of detecting all those attempts. The existing distributed IPSes, mainly based on mobile agent, have some serious problems, such as weak security of mobile agents, response latency, large code size. In this paper, we propose a customized intrusion prevention system, VMFence, in distributed virtual computing environment to simplify the complexity of the management. In VMFence, the states of detection processes vary with those of Virtual Machines (VMs), which are described by Deterministic Finite Automata (DFA). The detection processes, each of which detects one virtual machine, reside in a privileged virtual machine. The processes run synchronously and outside of VMs in order to achieve high performance and security. The experimental results also show VMFence has higher detection efficiency than traditional intrusion detection systems and little impact on the performance of the monitored VMs.
机译:入侵防御系统(IPS)是一种有效的工具,可用于检测和预防在访问和操纵计算机系统时主要通过网络和系统漏洞进行的有害尝试。入侵检测和防御是IPS的两个主要功能。随着攻击变得越来越庞大和复杂,传统的集中式IPS无法检测所有这些尝试。现有的主要基于移动代理的分布式IPS存在一些严重的问题,例如移动代理的安全性较弱,响应延迟,代码量大。在本文中,我们提出了一种在分布式虚拟计算环境中定制的入侵防御系统VMFence,以简化管理的复杂性。在VMFence中,检测过程的状态随虚拟机(VM)的状态而异,这由确定性有限自动机(DFA)描述。每个检测过程都检测一个虚拟机,它们位于特权虚拟机中。进程在VM外部同步运行,以实现高性能和安全性。实验结果还表明,VMFence具有比传统入侵检测系统更高的检测效率,并且对受监视VM的性能影响很小。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号