【24h】

Patch Auditing in Infrastructure as a Service Clouds

机译:基础架构即服务云中的补丁审核

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

A basic requirement of a secure computer system is that it be up to date with regard to software security patches. Unfortunately, Infrastructure as a Service (laaS) clouds make this difficult. They leverage virtualization, which provides functionality that causes traditional security patch update systems to fail. In addition, the diversity of operating systems and the distributed nature of administration in the cloud compound the problem of identifying unpatched machines. In this work, we propose P2, a hypervisor-based patch audit solution. P2 audits VMs and delects the execution of unpatched binary and non-binary files in an accurate, continuous and OS-agnostic manner. Two key innovations make P2 possible. First, P2 uses efficient information flow tracking to identify the use of unpatched non-binary files in a vulnerable way. We performed a patch survey and discover that 64% of files modified by security updates do not contain binary code, making the audit of non-binary files crucial. Second, P2 implements a novel algorithm that identifies binaries in mid-execution to allow handling of VMs resumed from a checkpoint or migrated into the cloud. We have implemented a prototype of P2 and and our experiments show that it accurately reports the execution of unpatched code while imposing performance overhead of 4%.
机译:安全计算机系统的基本要求是,它在软件安全补丁方面是最新的。不幸的是,基础架构即服务(laaS)云使这一点变得困难。他们利用虚拟化技术,虚拟化技术提供的功能会导致传统的安全补丁更新系统出现故障。此外,操作系统的多样性和云中管理的分布式性质使识别未修补机器的问题更加复杂。在这项工作中,我们提出了P2,这是基于管理程序的补丁审核解决方案。 P2审核虚拟机,并以准确,连续且与操作系统无关的方式决定未修补的二进制和非二进制文件的执行。两项关键的创新使P2成为可能。首先,P2使用有效的信息流跟踪以易受攻击的方式识别未修补的非二进制文件的使用。我们进行了补丁程序调查,发现安全更新修改的文​​件中有64%不包含二进制代码,因此对非二进制文件的审核至关重要。其次,P2实现了一种新颖的算法,该算法识别执行中的二进制文件,以允许处理从检查点恢复或迁移到云中的VM。我们已经实现了P2的原型,并且我们的实验表明,它可以准确地报告未修补的代码的执行情况,同时会产生4%的性能开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号