首页> 外文会议>Workshop on virtual machine security 2009 >TimeCapsule: Secure Recording of Accesses to a Protected Datastore
【24h】

TimeCapsule: Secure Recording of Accesses to a Protected Datastore

机译:TimeCapsule:安全记录对受保护数据存储区的访问

获取原文
获取原文并翻译 | 示例

摘要

We present an approach for transparently recording accesses to protected storage. In particular, we provide a framework for data monitoring in a virtualized environment using only the abstractions exposed by the hypervisor. To achieve our goals, we explore techniques for efficiently harvesting application code pages resident in memory at the time disk operations hit the I/O ring, and subsequently apply novel heuristics to overcome the "semantic gap" issue between file-system objects and disk blocks. Our forensic layer records all transactions in a version-based audit log that allows for faithful reconstruction of accesses to the datastore over time. We provide an empirical evaluation of our design that shows our approach to be promising, and very accurate in mapping application to block level access patterns-even under very noisy conditions.
机译:我们提出了一种透明地记录对受保护存储的访问的方法。特别是,我们提供了仅使用虚拟机监控程序公开的抽象在虚拟化环境中进行数据监视的框架。为了实现我们的目标,我们探索了在磁盘操作击中I / O环时有效地获取驻留在内存中的应用程序代码页的技术,并随后应用新颖的启发式方法来克服文件系统对象与磁盘块之间的“语义鸿沟”问题。我们的取证层将所有交易记录在基于版本的审核日志中,从而可以随着时间的推移忠实地重建对数据存储的访问。我们对设计进行了实证评估,表明我们的方法很有前途,并且即使在非常嘈杂的条件下,也可以非常准确地将应用程序映射到块级访问模式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号