首页> 外文会议>IEEE International Symposium on Parallel and Distributed Processing with Applications >Secure Logging for Auditable File System using Separate Virtual Machines
【24h】

Secure Logging for Auditable File System using Separate Virtual Machines

机译:使用单独的虚拟机安全地记录可审计文件系统

获取原文

摘要

Auditable file system is used to track the usage of the file system including the operations like read and write. Auditable file system keeps the trails of users' action and the trails are kept faithfully for future auditing. However, as the logs are still kept within the same file system, it will be quite vulnerable to be exposed as malware penetrating the system. Even with the file system hiding the logs, the skillful attacker can still analyze the on-disk structure to get and modify the logs. Thus the logs should be kept separate from the working system. Virtual machines can provide such separation as virtual machines can hold the whole operating system while still keep the system apart from the metal hardware. We propose a method of secure logging for auditable file system using a logging virtual machine. The logs are kept in another virtual machine safely. Even the working virtual machine is broken; the logs are not exposed to the outside. By the isolation provided by virtual machines, the logs can be kept safe and valid. The high privileged user can not modify the logs contents, or forge the logs and data to keep consistency, or pretend to be another user for doing un-authorized actions. We have done several works as well as a prototype system to show the feasibility of such approach. Experiments show that the logging virtual machine will not bring too much overhead.
机译:可讨厌的文件系统用于跟踪文件系统的使用,包括读写的操作。可审计文件系统保留用户操作的跟踪,并且对未来的审计持久地保持路径。但是,由于日志仍然保持在同一文件系统内,因此它将非常容易被暴露为穿透系统的恶意软件。即使文件系统隐藏了日志,熟练的攻击者仍然可以分析磁盘结构以获得和修改日志。因此,日志应该与工作系统分开。虚拟机可以提供这种分离,因为虚拟机可以保持整个操作系统,同时仍然保持系统与金属硬件相比。我们提出了一种使用日志记录虚拟机安全记录可审计文件系统的方法。日志安全地保存在另一个虚拟机中。即使是工作虚拟机也被打破了;日志不暴露在外面。通过虚拟机提供的隔离,日志可以保持安全且有效。高特权用户无法修改日志内容,或伪造日志和数据以保持一致性,或假装成为其他用户进行无授权操作。我们已经完成了几种作品以及原型系统,以显示这种方法的可行性。实验表明,测井虚拟机不会带来太多的开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号