首页> 外文期刊>Cloud Computing, IEEE Transactions on >ForenVisor: A Tool for Acquiring and Preserving Reliable Data in Cloud Live Forensics
【24h】

ForenVisor: A Tool for Acquiring and Preserving Reliable Data in Cloud Live Forensics

机译:ForenVisor:一种用于在Cloud Live取证中获取和保留可靠数据的工具

获取原文
获取原文并翻译 | 示例
           

摘要

Live forensics is an important technique in cloud security but is facing the challenge of reliability. Most of the live forensic tools in cloud computing run either in the target Operating System (OS), or as an extra hypervisor. The tools in the target OS are not reliable, since they might be deceived by the compromised OS. Furthermore, traditional general purpose hypervisors are vulnerable due to their huge code size. However, some modules of a general purpose hypervisor, such as device drivers, are indeed unnecessary for forensics. In this paper, we propose a special purpose hypervisor, called ForenVisor, which is dedicated to reliable live forensics. The reliability is improved in three ways: reducing Trusted Computing Base (TCB) size by leveraging a lightweight architecture, collecting evidence directly from the hardware, and protecting the evidence and other sensitive files with Filesafe module. We have implemented a proof-of-concept prototype on the Windows platform, which can acquire the process data, raw memory, and I/O data, such as keystrokes and network traffic. Furthermore, we evaluate ForenVisor in terms of code size, functionality, and performance. The experiment results show that ForenVisor has a relatively small TCB size of about 13 KLOC, and only causes less than 10 percent performance reduction to the target system. In particular, our experiments verify that ForenVisor can guarantee that the protected files remain untampered, even when the guest OS is compromised by viruses, such as ‘ILOVEYOU’ and Worm.WhBoy. Also, our system can be loaded as a hypervisor without needing to pause the target OS. This allows it to not only avoid destructing but also to gather the live evidence of the target OS. We also posted the source code of ForenVisor on Github.
机译:实时取证是云安全中的一项重要技术,但正面临可靠性挑战。云计算中的大多数实时取证工具都可以在目标操作系统(OS)中运行,也可以作为额外的管理程序运行。目标操作系统中的工具不可靠,因为它们可能会被受感染的操作系统欺骗。此外,传统的通用管理程序由于代码量巨大而容易受到攻击。但是,通用管理程序的某些模块(例如设备驱动程序)对于司法鉴定确实是不必要的。在本文中,我们提出了一个专用的管理程序,称为ForenVisor,专门用于可靠的现场取证。通过以下三种方式提高了可靠性:通过利用轻量级体系结构减小可信计算库(TCB)的大小,直接从硬件收集证据以及使用Filesafe模块保护证据和其他敏感文件。我们已经在Windows平台上实现了概念验证原型,该原型可以获取过程数据,原始内存和I / O数据,例如击键和网络流量。此外,我们在代码大小,功能和性能方面评估了ForenVisor。实验结果表明,ForenVisor的TCB大小相对较小,约为13 KLOC,并且只会导致目标系统的性能下降不到10%。特别是,我们的实验证明,即使来宾操作系统受到“ ILOVEYOU”和Worm.WhBoy等病毒的威胁,ForenVisor仍可以保证受保护的文件不受干扰。同样,我们的系统可以作为虚拟机监控程序加载,而无需暂停目标操作系统。这样不仅可以避免破坏,还可以收集目标操作系统的实时证据。我们还在Github上发布了ForenVisor的源代码。

著录项

  • 来源
    《Cloud Computing, IEEE Transactions on》 |2017年第3期|443-456|共14页
  • 作者单位

    School of Software, and the Shanghai Key Laboratory of Scalable Computing and Systems, Shanghai Jiao Tong University, Shanghai, China;

    School of Software, and the Shanghai Key Laboratory of Scalable Computing and Systems, Shanghai Jiao Tong University, Shanghai, China;

    Shanghai Key Laboratory of Scalable Computing and Systems, Department of Computer Science, Shanghai Jiao Tong University, Shanghai, China;

    School of Software, and the Shanghai Key Laboratory of Scalable Computing and Systems, Shanghai Jiao Tong University, Shanghai, China;

    Shanghai Key Laboratory of Scalable Computing and Systems, Department of Computer Science, Shanghai Jiao Tong University, Shanghai, China;

    Department of Computer and Information Sciences at Fordham University, Bronx;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Virtualization; Virtual machine monitors; Reliability; Forensics; Cloud computing; Hardware; Performance evaluation;

    机译:虚拟化;虚拟机监视器;可靠性;取证;云计算;硬件;性能评估;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号