首页> 外文会议>Workshop on virtual machine security >TimeCapsule: Secure Recording of Accesses to a Protected Datastore
【24h】

TimeCapsule: Secure Recording of Accesses to a Protected Datastore

机译:TimeCapsule:安全录制访问受保护的数据存储

获取原文

摘要

We present an approach for transparently recording accesses to protected storage. In particular, we provide a framework for data monitoring in a virtualized environment using only the abstractions exposed by the hypervisor. To achieve our goals, we explore techniques for efficiently harvesting application code pages resident in memory at the time disk operations hit the I/O ring, and subsequently apply novel heuristics to overcome the "semantic gap" issue between file-system objects and disk blocks. Our forensic layer records all transactions in a version-based audit log that allows for faithful reconstruction of accesses to the datastore over time. We provide an empirical evaluation of our design that shows our approach to be promising, and very accurate in mapping application to block level access patterns-even under very noisy conditions.
机译:我们提出了一种透明地记录到受保护存储的方法。特别是,我们仅使用虚拟机管理程序暴露的抽象提供虚拟化环境中的数据监视的框架。为实现目标,我们探讨了在I / O环的时间磁盘操作中有效地收集驻留在内存中的应用程序代码页的技术,随后申请新的启发式方法来克服文件系统对象和磁盘块之间的“语义差距”问题。我们的法医层记录了基于版本的审核日志中的所有交易,允许忠实地重建访问数据存储的时间。我们为我们的设计提供了一个实证评估,显示我们的方法是有希望的方法,并且在映射应用程序到阻止级别访问模式 - 即使在非常嘈杂的条件下也是如此准确。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号