跳到主要导航 跳到搜索 跳到主要内容

Shadowmonitor: An effective in-VM monitoring framework with hardware-enforced isolation

  • Bin Shi
  • , Lei Cui*
  • , Bo Li
  • , Xudong Liu
  • , Zhiyu Hao
  • , Haiying Shen
  • *此作品的通讯作者
  • Beihang University
  • CAS - Institute of Information Engineering
  • University of Virginia

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Virtual machine introspection (VMI) is one compelling technique to enhance system security in clouds. It is able to provide strong isolation between untrusted guests and security tools placed in guests, thereby enabling dependability of the security tools even if the guest has been compromised. Due to this benefit, VMI has been widely used for cloud security such as intrusion detection, security monitoring, and tampering forensics. However, existing VMI solutions suffer significant performance degradation mainly due to the high overhead upon frequent memory address translations and context-switches. This drawback limits its usage in many real-world scenarios, especially when fine-grained monitoring is desired. In this paper, we present ShadowMonitor, an effective VMI framework that enables efficient in-VM monitoring without imposing significant overhead. ShadowMonitor decomposes the whole monitoring system into two compartments and then assigns each compartment with isolated address space. By placing the monitored components in the protected compartment, ShadowMonitor guarantees the safety of both monitoring tools and guests. In addition, ShadowMonitor employs hardware-enforced instructions to design the gates across two compartments, thereby providing efficient switching between compartments. We have implemented ShadowMonitor on QEMU/KVM exploiting several hardware virtualization features. The experimental results show that ShadowMonitor could prevent several types of attacks and achieves 10× speedup over the existing method in terms of both event monitoring and overall application performance.

源语言英语
主期刊名Research in Attacks, Intrusions, and Defenses - 21st International Symposium, RAID 2018, Proceedings
编辑Michael Bailey, Thorsten Holz, Manolis Stamatogiannakis, Sotiris Ioannidis
出版商Springer Verlag
670-690
页数21
ISBN(印刷版)9783030004699
DOI
出版状态已出版 - 2018
活动21st International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2018 - Heraklion, 希腊
期限: 10 9月 201812 9月 2018

丛书

姓名Lecture Notes in Computer Science
11050 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议21st International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2018
国家/地区希腊
Heraklion
时期10/09/1812/09/18

学术指纹

探究 'Shadowmonitor: An effective in-VM monitoring framework with hardware-enforced isolation' 的科研主题。它们共同构成独一无二的学术指纹。

引用此