Checking virtual machine kernel control-flow integrity using a page-level dynamic tracing approach
Autor: | Binxing Fang, Dongyang Zhan, Xiaojiang Du, Lin Ye, Hongli Zhang |
---|---|
Rok vydání: | 2017 |
Předmět: |
sysfs
Computer science 020206 networking & telecommunications 02 engineering and technology Tracing computer.software_genre Theoretical Computer Science Configfs Kernel preemption Virtual machine Kernel (statistics) 0202 electrical engineering electronic engineering information engineering Operating system Overhead (computing) 020201 artificial intelligence & image processing Geometry and Topology Page computer Software |
Zdroj: | Soft Computing. 22:7977-7987 |
ISSN: | 1433-7479 1432-7643 |
Popis: | Kernel control-flow integrity (CFI) of virtual machines is very important to cloud security. VMI-based dynamic tracing and analyzing methods are promising options for checking kernel CFI in cloud. However, the CFI monitors based on tracing always work at instruction or branch level and result in serious virtual machine performance degradation. To meet the performance requirements in the cloud, we present a page-level dynamic VMI-based kernel CFI checking solution. We trace VM kernel execution at page level, which means that the in-page instruction execution cannot trigger our monitor. As a result, the tracing overhead can be greatly reduced. Based on page-level execution information, we propose two policies to describe the kernel control-flow so as to build the secure kernel control-flow database in the learning stage. In the monitoring stage, we compare runtime execution information with the secure database to check kernel CFI. To further reduce the monitoring overhead, we propose two performance optimization strategies. We implement the prototype on Xen and leverage hardware events to trace VM memory page execution. Then, we evaluate the effectiveness and performance of the prototype. The experimental results prove that our system has enough detection capability and the overhead is acceptable. |
Databáze: | OpenAIRE |
Externí odkaz: |