首页> 外文期刊>Concurrency and computation: practice and experience >OB-IMA: out-of-the-box integrity measurement approach for guest virtual machines
【24h】

OB-IMA: out-of-the-box integrity measurement approach for guest virtual machines

机译:OB-IMA:来宾虚拟机的即用型完整性度量方法

获取原文
获取原文并翻译 | 示例

摘要

Infrastructure as a Service cloud provides elasticity and scalable virtual machines (VMs) as computingrnservice to multiple tenants, but the tenants lose the full control of their data. Measuring the integrity ofrncritical files of the VMs and providing the integrity attestation to the tenants on the basis of TCG trustedrncomputing techniques is an effective way to alleviate their anxiety. This paper considers how to measurernthe integrity of the processes run in guest VMs and files opened in guest VMs. We propose an out-of-theboxrnintegrity measurement approach to measure the integrity of critical files through system call (syscall)rninterception without any modification of the guest VMs. Out-of-the-box integrity measurement approachrncan not only measure the integrity of all files that have been considered by existing approaches but alsornmeasure the integrity of the system configuration files, program loaders, and script interpreters, which affectrnthe system behaviors and integrity. The ability of supporting both system and manual measurement policiesrnmakes our approach flexible. We implement this approach in Xen hypervisor with little modification of thernexisting syscall interception method, and this approach can be ported to other virtualization platform easily.
机译:基础架构即服务云为多个租户提供了弹性和可扩展的虚拟机(VM)作为计算服务,但租户失去了对其数据的完全控制权。在TCG可信计算技术的基础上,测量VM的关键文件的完整性并向租户提供完整性证明是缓解其焦虑的有效方法。本文考虑了如何衡量来宾VM中运行的进程和来宾VM中打开的文件的完整性。我们提出了一种开箱即用的完整性测量方法,该方法可通过系统调用(syscall)拦截来测量关键文件的完整性,而无需对来宾VM进行任何修改。开箱即用的完整性度量方法不仅可以度量现有方法已经考虑过的所有文件的完整性,而且可以度量影响系统行为和完整性的系统配置文件,程序加载器和脚本解释器的完整性。同时支持系统和手动测量策略的能力使我们的方法更加灵活。我们在Xen虚拟机管理程序中实现了该方法,而对现有的系统调用拦截方法几乎没有任何修改,并且可以轻松地将该方法移植到其他虚拟化平台。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号