首页> 外文期刊>International journal of grid and high performance computing >TVGuarder: A Trace-Enable Virtualization Protection Framework against Insider Threats for laaS Environments
【24h】

TVGuarder: A Trace-Enable Virtualization Protection Framework against Insider Threats for laaS Environments

机译:TVGuarder:针对laaS环境的内部威胁的跟踪启用虚拟化保护框架

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Cloud computing has a most vulnerable security concerns as virtualization. This paper presents a Trace-enable Virtualization protection framework named TVGuarder, which protects IaaS user's important data from being illegally accessed or maliciously damaged by insider attacks. A threat model is established to characterize cloud-oriented insider attacks and countermeasures are proposed in TVGuarder. First, LSM hooks in host OS kernel are leveraged to enforce that VM images could only be accessed by host virtualization service. Second, a trusted loading mechanism is proposed to prevent tampered or disguised virtualization process from being executed in Host OS. Third, a log-based back tracing mechanism is designed to record full call trace of VM operations and guarantee that only legitimate VM operations are allowed. TVGuarder has been implemented in Openstack platform and several comprehensive experiments are conducted. Experimental results show that TVGuarder can identify several important insider attacks and protect virtual machine images with only a small performance degradation.
机译:云计算作为虚拟化具有最脆弱的安全问题。本文提出了一个名为TVGuarder的可启用跟踪的虚拟化保护框架,该框架可保护IaaS用户的重要数据免遭内部人员攻击而非法访问或恶意破坏。建立了威胁模型来表征面向云的内部攻击,并在TVGuarder中提出了对策。首先,利用主机OS内核中的LSM挂钩来强制VM映像只能由主机虚拟化服务访问。其次,提出了一种受信任的加载机制,以防止篡改或伪装的虚拟化过程在主机OS中执行。第三,基于日志的回溯机制旨在记录VM操作的完整调用跟踪,并确保仅允许合法的VM操作。 TVGuarder已在Openstack平台中实现,并进行了一些综合实验。实验结果表明,TVGuarder可以识别几种重要的内部攻击并以很小的性能下降保护虚拟机映像。

著录项

  • 来源
  • 作者单位

    College of Computer Science, Faculty of Information Technology, Beijing University of Technology, Beijing, China;

    College of Computer Science, Faculty of Information Technology, Beijing University of Technology, Beijing, China;

    State Key Laboratory of Software Development Environment, Beihang University, Beijing, China;

    College of Computer Science, Faculty of Information Technology, Beijing University of Technology, Beijing, China;

    College of Computer Science, Faculty of Information Technology, Beijing University of Technology, Beijing, China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Cloud Security; Insider Attackers; Trace-Enable Protection; Virtualization; VM Image Files;

    机译:云安全;内部攻击者;跟踪启用保护;虚拟化;VM映像文件;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号