【24h】

TimeVM

机译:荣誉

获取原文

摘要

Network intrusions become a signification threat to network servers and its availability. A simple intrusion can suspend the organization's network services and can lead to a financial disaster. In this paper, we propose a framework called TimeVM to mitigate, or even eliminate, the infection of a network intrusion on-line as fast as possible. The framework is based on the virtual machine technology and traffic-replay-based recovery. TimeVM gives the illusion of "time machine". TimeVM logs only the network traffic to a server and replays the logged traffic to multiple "shadow" virtual machines (Shadow VM) after different time delays (time lags). Consequently, each Shadow VM will represent the server at different time in history. When attack/infection is detected, TimeVM enables navigating through the traffic history (logs), picking uninfected Shadow VM, removing the attack traffic, and then fast-replaying the entire traffic history to this Shadow VM. As a result, a typical up-to-date uninfectedversion of the original system can be constructed.
机译:网络入侵成为网络服务器的签证威胁及其可用性。简单的入侵可以暂停组织的网络服务,可以导致金融灾难。在本文中,我们提出了一个名为TimeVM的框架,以缓解,甚至消除,尽可能快地将网络侵入感染。该框架基于虚拟机技术和基于流量的交通恢复。 TimeVM给出了“Time Machine”的错觉。 TimeVM仅在不同的时间延迟(时间滞后)之后重放到服务器的网络流量并重放记录流量到多个“阴影”虚拟机(Shadow VM)。因此,每个影子VM将在历史中不同时间代表服务器。当检测到攻击/感染时,TimeVM使能够通过流量历史(日志)导航,从而挑选未感染的影子VM,删除攻击流量,然后快速重播整个流量历史记录到此影子VM。结果,可以构建原始系统的典型最新的未传记。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号