首页> 外文会议>Proceedings of the IASTED Multiconferences >THE SECURE MIGRATION OF A VIRTUAL MACHINE INTROSPECTION INTRUSION DETECTION SYSTEM
【24h】

THE SECURE MIGRATION OF A VIRTUAL MACHINE INTROSPECTION INTRUSION DETECTION SYSTEM

机译:虚拟机自检入侵检测系统的安全迁移

获取原文
获取原文并翻译 | 示例

摘要

This paper presents a method to perform a live migration ofrna virtual machine introspection (VMI) intrusion detectionrnsystem (IDS) from one physical node to another with itsrnassociated virtual machine (VM). This is extremely importantrnas more attention is given to VMI IDSes in the areas ofrnboth Enterprise and Cloud Computing environments wherernlive migration is utilized for load balancing and fault tolerance.rnCurrent VMI IDS systems neglect the live migrationrncapabilities of VMs restricting the monitored VM tornthat specific node. Our work is to investigate the potentialrnmethodologies to perform this task such that VMI IDSesrnbecome feasible within practical computing environments.rnWe have designed a methodology to accomplish this goalrnand extended the VMI IDS known as the virtual systemlevelrnlightweight integrity monitor (vSLIM) in order to validaternour work. We have evaluated this design using manin-rnthe-middle attacks which modify the VM during transitrnin order to verify the correctness of our design and foundrnless than 3% overhead when compared to the cost of migratingrna VM without a VMI IDS. Likewise, the cost ofrnthis migration provides little impact on the performance ofrnco-located VMs.
机译:本文提出了一种使用其关联的虚拟机(VM)从一个物理节点向另一个物理节点实时迁移虚拟机自检(VMI)入侵检测系统(IDS)的方法。这对于企业和云计算环境中的VMI IDS极为重要,在这些环境中,实时迁移被用于负载平衡和容错。当前的VMI IDS系统忽略了虚拟机的实时迁移功能,从而限制了受监控的虚拟机到该特定节点。我们的工作是研究执行此任务的潜在方法,以使VMI IDS在实际计算环境中变得可行。我们设计了一种方法来实现此目标,并扩展了称为虚拟系统级轻量级完整性监视器(vSLIM)的VMI IDS,以验证工作。我们使用中间人攻击对这种设计进行了评估,该攻击在传输过程中对VM进行了修改,以验证我们设计的正确性,与不使用VMI IDS的VM迁移相比,开销只有不到3%。同样,此迁移的成本几乎不会影响位于同一地点的VM的性能。

著录项

  • 来源
  • 会议地点 Innsbruck(AU)
  • 作者单位

    Electrical and Computer Engineering Tennessee Technological University Cookeville, TN, USA email: wfaderhold21@students.tntech.edu;

    Electrical and Computer Engineering Oak Ridge National Laboratory Oak Ridge, TN, USA Computer Science and Mathematics Division Oak Ridge National Laboratory Oak Ridge, TN, USA email: scottsl@ornl.gov;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Cloud Computing; Network Security;

    机译:云计算;;网络安全;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号