首页> 外文会议>International Symposium on Computer Architecture and High Performance Computing >Virtual-Machine-based Intrusion Detection on File-aware Block Level Storage
【24h】

Virtual-Machine-based Intrusion Detection on File-aware Block Level Storage

机译:基于虚拟机的入侵检测文件感知块级存储

获取原文

摘要

In this paper we present a storage-based intrusion detection system (IDS) that makes use of advantages of virtual machine (VM) and smart disk technologies. The virtual machine monitor (VMM) can prevent the IDS itself from potential attacks while the smart disk technology provides IDS with a whole view of the file system of the monitored VM. We show how to use a tool and some file system knowledge to enable the virtual disk to maintain a sector-to-file mapping table (called file-aware block level storage) as well as how to detect the changes to file content on-line. Based on these features, normal file-level intrusion detection (ID) rules can be converted to sector-level ones in order to integrate ID functions to the virtual storage. We implement such a prototype based on QEMU VMM and the OS of VM is Windows XP. Moreover the time overhead introduced by this solution is tested.
机译:在本文中,我们提供了一种基于存储的入侵检测系统(ID),它利用虚拟机(VM)和智能磁盘技术的优点。虚拟机监视器(VMM)可以防止IDS自身来自潜在攻击,而智能磁盘技术提供具有监控VM文件系统的整个视图的ID。我们展示了如何使用工具和一些文件系统知识来使虚拟磁盘能够维护扇区到文件映射表(称为文件感知块级别存储)以及如何检测到在线内容的更改。基于这些功能,可以将正常的文件级入侵检测(ID)规则转换为扇区级别,以便将ID函数集成到虚拟存储。我们根据QEMU VMM实现此类原型,VM的OS是Windows XP。此外,测试了该解决方案引入的时间开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号