KVMIveggur: Flexible, secure, and efficient support for self-service virtual machine introspection

被引:3
|
作者
Sentanoe, Stewart [1 ]
Dangl, Thomas [1 ]
Reiser, Hans P. [1 ,2 ]
机构
[1] Univ Passau, Innstr 43, D-94032 Passau, Germany
[2] Reykjavik Univ, Menntavegur 1, IS-102 Reykjavik, Iceland
关键词
Virtual machine introspection; Virtual machine; KVM; Access control;
D O I
10.1016/j.fsidi.2022.301397
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Virtual machine introspection (VMI) has evolved into a widely used technique for purposes such as digital forensics, intrusion detection, and malware analysis. The recent integration of enhanced VMI capabilities into KVM further facilitates the use of VMI. A significant obstacle, however, remains: VMI usually requires highly privileged access to the host system. Existing research prototypes that address this issue either target only the Xen hypervisor, are extremely slow, offer only a subset of the desired functionality, or are hard to deploy in real-life systems. We present our flexible KVMIveggur architecture as a novel solution to these challenges. It offers three flavors of isolation (using containers, virtual machines, and network remote access) that all enable access control for secure self-service VMI in cloud environments. It enables the full use of passive and active VMI, supports continuous monitoring also during live VM migration, and can be tailored for low overhead and minimal resource utilization on the host system. The experimental evaluation of our prototype demonstrates the feasibility and the efficiency of our approach and provides detailed insights into the differences between the three flavors. (C) 2022 The Authors. Published by Elsevier Ltd.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] CloudVMI: Virtual Machine Introspection as a Cloud Service
    Baek, Hyun-wook
    Srivastava, Abhinav
    Van der Merwe, Jacobus
    2014 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E), 2014, : 153 - 158
  • [2] Efficient Checkpointing of Virtual Machines using Virtual Machine Introspection
    Aderholdt, Ferrol
    Han, Fang
    Scott, Stephen L.
    Naughton, Thomas
    2014 14TH IEEE/ACM INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND GRID COMPUTING (CCGRID), 2014, : 414 - 423
  • [3] Cloud API Support for Self-service Virtual Network Function (VNF) Deployment
    Baucke, Stephan
    Kempf, James
    Ben Ali, Racha
    Ramachandran, Anirudh
    Seetharaman, Srini
    2015 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORK (NFV-SDN), 2015, : 40 - 46
  • [4] VMIFresh: Efficient and fresh caches for virtual machine introspection
    Dangl, Thomas
    Sentanoe, Stewart
    Reiser, Hans P.
    COMPUTERS & SECURITY, 2023, 135
  • [5] VMIFresh: Efficient and Fresh Caches for Virtual Machine Introspection
    Dangl, Thomas
    Sentanoe, Stewart
    Reiser, Hans P.
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022, 2022,
  • [6] AutoThing: A Secure Transaction Framework for Self-Service Things
    Ivanov, Nikolay
    Yan, Qiben
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2023, 16 (02) : 983 - 995
  • [7] Exploring Self-Service Support Methods in IT Service Management
    Jantti, Marko
    2013 10TH INTERNATIONAL CONFERENCE ON SERVICE SYSTEMS AND SERVICE MANAGEMENT (ICSSSM), 2013, : 179 - 184
  • [8] CryptVMI: A Flexible and Encrypted Virtual Machine Introspection System in the Cloud
    Yao, Fangzhou
    Sprabery, Read
    Campbell, Roy H.
    SCC'14: PROCEEDINGS OF THE 2ND INTERNATIONAL WORKSHOP ON SECURITY IN CLOUD COMPUTING, 2014, : 11 - 17
  • [9] Preliminary Exploration of Technology Acceptance for Applying Virtual Assistants in Clinic Self-service Machine
    Tang, Chien
    Chen, Chun-Ching
    HCI INTERNATIONAL 2024 POSTERS, PT I, HCII 2024, 2024, 2114 : 206 - 214
  • [10] Support for Self-service Automated Parking Systems
    Baranovski, Igor
    Stankovski, Stevan
    Ostojic, Gordana
    Horvat, Sabolo
    2020 19TH INTERNATIONAL SYMPOSIUM INFOTEH-JAHORINA (INFOTEH), 2020,