...
首页> 外文期刊>Future generation computer systems >A novel integrity measurement method based on copy-on-write for region in virtual machine
【24h】

A novel integrity measurement method based on copy-on-write for region in virtual machine

机译:一种基于虚拟机中区域复制写入的新型完整性测量方法

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

More and more enterprises are migrating services and data into virtual machine (VM) using base and increment, and the files in the VM may contain critical data. Therefore, it is necessary to build a trusted environment to enhance the security of the files in VM by the integrity measurement methods (IMMs). In order to simplify the management of the files in integrity measurement, the security manager needs to put these files into one region and then to measures the integrity of the region. If the region is integrity, the files in that region are integrity too. Currently, the traditional IMMs are all based on the message digest algorithms that use too much amount of data, spend much time, and make the performance of VMs degraded. Aiming to address those problems, we propose a novel IMM based on copy-on-write for the region, called RIMM. The method puts the region into the base image, gets the integrity information of the region from the base image by the structures of image and region, and periodically measures the integrity of the region in the increment image by the structure of image and copy-on-write. It is transparent for VM and can eliminate the semantic gap. The evaluation shows that the RIMM can significantly reduce the amount of data and time in the process of integrity measurement. For example, (1) when the region size is 100MB, the amount of data used by RIMM is about 400 times smaller than that used by IMMs based on MD5; the time spent by RIMM is about 600 times less than that used by 1MMs based on MD5. (2) when the region size is 9GB, the amount of data used by RIMM is about 29000 times smaller than that used by IMMs based on MD5; the time spent by RIMM is about 3864 times less than that used by IMMs based on MD5. (C) 2019 Published by Elsevier B.V.
机译:越来越多的企业正在使用基础和增量将服务和数据迁移到虚拟机(VM),并且VM中的文件可能包含关键数据。因此,有必要建立一个可信环境,以通过完整性测量方法(IMM)来增强VM中的文件的安全性。为了简化完整性测量中文件的管理,安全管理器需要将这些文件放入一个区域,然后测量该区域的完整性。如果该区域是完整性的,则该区域中的文件也是完整性的。目前,传统的IMMI基于消息摘要算法,使用过多的数据量,花费很多时间,并使VM的性能降低。旨在解决这些问题,我们提出了一种基于对该地区的撰写,称为RIMM的撰写。该方法将区域放入基础图像中,通过图像和区域的结构获取从基本图像的区域的完整性信息,并通过图像和复制的结构周期性地测量增量图像中的区域的完整性-写。对于VM来说是透明的,可以消除语义差距。评估表明,RIMM可以显着减少完整性测量过程中的数据量和时间。例如,(1)当区域尺寸为100MB时,RIMM使用的数据量小于IMM用于基于MD5的400倍。 RIMM所花费的时间比基于MD5的1MMS使用的时间少600倍。 (2)当区域尺寸为9GB时,RIMM使用的数据量比IMM 5的基于MD5小的数据小约29000倍; RIMM花费的时间比仅在MD5的IMM少3864倍。 (c)2019年由elestvier b.v发布。

著录项

  • 来源
    《Future generation computer systems》 |2019年第8期|714-726|共13页
  • 作者单位

    Beihang Univ State Key Lab Software Dev Environm Beijing 100191 Peoples R China|Beihang Univ Sch Comp Sci & Engn Beijing 100191 Peoples R China|Nanyang Normal Univ Sch Comp & Informat Technol Nanyang 473061 Henan Peoples R China;

    Beihang Univ State Key Lab Software Dev Environm Beijing 100191 Peoples R China|Beihang Univ Sch Comp Sci & Engn Beijing 100191 Peoples R China;

    Beihang Univ State Key Lab Software Dev Environm Beijing 100191 Peoples R China|Beihang Univ Sch Comp Sci & Engn Beijing 100191 Peoples R China;

    Beihang Univ State Key Lab Software Dev Environm Beijing 100191 Peoples R China|Beihang Univ Sch Comp Sci & Engn Beijing 100191 Peoples R China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Integrity measurement method; Copy-on-write; Virtual machine; Base and increment image; Security; Region;

    机译:完整性测量方法;编写复制;虚拟机;基础和增量图像;安全;区域;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号