首页> 外文期刊>Journal of Parallel and Distributed Computing >KASLR-MT: Kernel Address Space Layout Randomization for Multi-Tenant cloud systems
【24h】

KASLR-MT: Kernel Address Space Layout Randomization for Multi-Tenant cloud systems

机译:KASLR-MT:内核地址多租户云系统的空间布局随机化

获取原文
获取原文并翻译 | 示例

摘要

Cloud computing has completely changed our lives. This technology dramatically impacted on how we play, work and live. It has been widely adopted in many sectors mainly because it reduces the cost of performing tasks in a flexible, scalable and reliable way. To provide a secure cloud computing architecture, the highest possible level of protection must be applied. Unfortunately, the cloud computing paradigm introduces new scenarios where security protection techniques are weakened or disabled to obtain a better performance and resources exploitation. Kernel ASLR (KASLR) is a widely adopted protection technique present in all modern operating systems. KASLR is a very effective technique that thwarts unknown attacks but unfortunately its randomness have a significant impact on memory deduplication savings. Both techniques are very desired by the industry, the first one because of the high level of security that it provides and the latter to obtain better performance and resources exploitation. In this paper, we propose KASLR-MT, a new Linux kernel randomization approach compatible with memory deduplication. We identify why the most widely and effective technique used to mitigate attacks at kernel level, KASLR, fails to provide protection and shareability at the same time. We analyze the current Linux kernel randomization and how it affects to the shared memory of each kernel region. Then, based on the analysis, we propose KASLR-MT, the first effective and practical Kernel ASLR memory protection that maximizes the memory deduplication savings rate while providing a strong security. Our tests reveal that KASLR-MT is not intrusive, very scalable and provides strong protection without sacrificing the shareability.
机译:云计算完全改变了我们的生活。这项技术会显着影响我们如何玩耍,工作和生活。它已被广泛采用,主要是因为它以灵活,可扩展和可靠的方式执行执行任务的成本。为了提供安全的云计算架构,必须应用最高可能的保护级别。不幸的是,云计算范例介绍了安全保护技术被削弱或禁用的新方案,以获得更好的性能和资源开发。内核ASLR(KASLR)是所有现代操作系统中的广泛采用的保护技术。 KASLR是一种非常有效的技术,阻止未知的攻击,但不幸的是,它的随机性对记忆重复数据删除的储蓄产生了重大影响。这两种技术由行业非常希望,这是第一个,因为它提供了高度的安全性和后者获得更好的性能和资源利用。在本文中,我们提出了一种与内存重复数据删除兼容的新型Linux内核随机化方法Kaslr-MT。我们确定了为什么用于缓解内核级别的攻击,KASLR的最广泛和有效的技术未能同时提供保护和享用率。我们分析当前的Linux内核随机化以及它如何影响每个内核区域的共享内存。然后,根据分析,我们提出了KASLR-MT,这是第一种有效和实用的内核ASLR内存保护,可以最大限度地提高内存重复数据删除率,同时提供强大的安全性。我们的测试表明,KASLR-MT并不侵入,非常可扩展,并提供强烈的保护,而不会牺牲枯萎病。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号