首页> 外文期刊>Journal of information science and engineering >A Secure and Efficient Kernel Log Transfer Mechanism for Virtualization Environments
【24h】

A Secure and Efficient Kernel Log Transfer Mechanism for Virtualization Environments

机译:用于虚拟化环境的安全高效的内核日志传输机制

获取原文
获取原文并翻译 | 示例

摘要

Kernel logs are very important source of information for administrators to reconstruct security events. Once a sophisticated attacker intrudes a computer system, he (or she) may manipulate the kernel log to clear up the intrusion evidence. Previous solutions suffer from limitations in that: 1) Some methods do not provide adequate protection; 2) Some methods are not compatible with the existing systems or hardware; 3) Some methods incur considerable performance overhead. In this paper, we present SEKEL, a secure and efficient kernel log transfer mechanism based on virtualization technology. The basic idea of our approach is to decouple the kernel log collection and transfer procedures into two concurrent components. On one hand, the log collection component protected by the SIM framework is deployed in the target VM. On the other hand, the log transfer component is placed into a trusted execution environment for performance isolation. To deal with the synchronization problem introduced by our concurrent components, we extend Lamport's ring buffer algorithm. The evaluation shows that SEKEL can protect kernel logs effectively with little performance degradation.
机译:内核日志是管理员重建安全事件的非常重要的信息来源。一旦老练的攻击者入侵计算机系统,他(或她)就可以操纵内核日志来清除入侵证据。先前的解决方案具有以下局限性:1)有些方法不能提供足够的保护; 2)有些方法与现有系统或硬件不兼容; 3)一些方法会产生相当大的性能开销。在本文中,我们介绍了SEKEL,这是一种基于虚拟化技术的安全高效的内核日志传输机制。我们方法的基本思想是将内核日志收集和传输过程分离为两个并发组件。一方面,受SIM框架保护的日志收集组件已部署在目标VM中。另一方面,日志传输组件放置在受信任的执行环境中以实现性能隔离。为了处理并发组件引入的同步问题,我们扩展了Lamport的环形缓冲区算法。评估显示SEKEL可以有效保护内核日志,而性能几乎没有下降。

著录项

  • 来源
    《Journal of information science and engineering》 |2016年第5期|1131-1143|共13页
  • 作者单位

    Beijing Inst Technol, Beijing Key Lab Software Secur Engn Tech, Beijing 100081, Peoples R China|Yunnan Minzu Univ, Shanghai Key Lab Integrated Adm Technol Informat, Kunming 650500, Peoples R China;

    Yunnan Minzu Univ, Key Lab IOT Applicat Technol Univ Yunnan Prov, Kunming 650500, Peoples R China;

    Beijing Inst Technol, Beijing Key Lab Software Secur Engn Tech, Beijing 100081, Peoples R China;

    Beijing Inst Technol, Beijing Key Lab Software Secur Engn Tech, Beijing 100081, Peoples R China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    kernel log transfer; virtualization; concurrent; synchronization; protect;

    机译:内核日志传输虚拟化并发同步保护;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号