首页> 外文期刊>Soft computing: A fusion of foundations, methodologies and applications >Checking virtual machine kernel control-flow integrity using a page-level dynamic tracing approach
【24h】

Checking virtual machine kernel control-flow integrity using a page-level dynamic tracing approach

机译:使用页面级动态跟踪方法检查虚拟机内核控制流程完整性

获取原文
获取原文并翻译 | 示例
           

摘要

Kernel control-flow integrity (CFI) of virtual machines is very important to cloud security. VMI-based dynamic tracing and analyzing methods are promising options for checking kernel CFI in cloud. However, the CFI monitors based on tracing always work at instruction or branch level and result in serious virtual machine performance degradation. To meet the performance requirements in the cloud, we present a page-level dynamic VMI-based kernel CFI checking solution. We trace VM kernel execution at page level, which means that the in-page instruction execution cannot trigger our monitor. As a result, the tracing overhead can be greatly reduced. Based on page-level execution information, we propose two policies to describe the kernel control-flow so as to build the secure kernel control-flow database in the learning stage. In the monitoring stage, we compare runtime execution information with the secure database to check kernel CFI. To further reduce the monitoring overhead, we propose two performance optimization strategies. We implement the prototype on Xen and leverage hardware events to trace VM memory page execution. Then, we evaluate the effectiveness and performance of the prototype. The experimental results prove that our system has enough detection capability and the overhead is acceptable.
机译:虚拟机的内核控制流程(CFI)对云安全非常重要。基于VMI的动态跟踪和分析方法是在云中检查内核CFI的有希望的选项。但是,基于跟踪的CFI监视器始终在指令或分支级别工作,并导致严重的虚拟机性能下降。为了满足云中的性能要求,我们呈现了一种基于页面级动态VMI的内核CFI检查解决方案。我们在页面级别跟踪VM内核执行,这意味着IN-PAGE指令执行无法触发我们的监视器。结果,可以大大减少跟踪开销。基于页面级执行信息,我们提出了两种策略来描述内核控制流程,以便在学习阶段构建安全内核控制流数据库。在监视阶段,我们将运行时执行信息与安全数据库进行比较以检查内核CFI。为了进一步减少监测开销,我们提出了两种性能优化策略。我们在Xen上实现原型并利用硬件事件来跟踪VM内存页面执行。然后,我们评估原型的有效性和性能。实验结果证明,我们的系统具有足够的检测能力,并且开销是可接受的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号