A Self-protection Mechanism against Stepping-stone Attacks for IaaS Clouds

被引:9
作者
Kourai, Kenichi [1 ]
Azumi, Takeshi [2 ]
Chiba, Shigeru [3 ]
机构
[1] Kyushu Inst Technol, Fukuoka, Japan
[2] Tokyo Inst Technol, Meguro, Tokyo, Japan
[3] Univ Tokyo, Tokyo 1138654, Japan
来源
2012 9TH INTERNATIONAL CONFERENCE ON UBIQUITOUS INTELLIGENCE & COMPUTING AND 9TH INTERNATIONAL CONFERENCE ON AUTONOMIC & TRUSTED COMPUTING (UIC/ATC) | 2012年
关键词
Virtual machines; operating systems; cloud computing; packet filtering; outgoing attacks;
D O I
10.1109/UIC-ATC.2012.139
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
For Infrastructure-as-a-Service (IaaS) clouds, stepping-stone attacks via hosted virtual machines (VMs) are critical. This type of attack uses compromised VMs as stepping stones for attacking the outside hosts. Not only compromised VMs but also IaaS providers are regarded as attackers. For self-protection, IaaS clouds should perform active response against stepping-stone attacks. However, it is difficult to stop only outgoing attacks at edge firewalls of clouds because edge firewalls can use only information in network packets. In this paper, we propose a new self-protection mechanism against stepping-stone attacks for IaaS clouds, which is called xFilter. xFilter is a packet filter running in the virtual machine monitor (VMM) underlying VMs and achieves pinpoint active response by using VM introspection. VM introspection enables xFilter in the VMM to obtain information on packet senders directly from the memory of VMs. When xFilter detects outgoing attacks, it automatically generates appropriate filtering rules with information on sender processes. Our experiments showed that xFilter could stop only outgoing attacks as much as possible. The performance degradation due to xFilter was less than 13 % in usual cases.
引用
收藏
页码:539 / 546
页数:8
相关论文
共 12 条
[1]  
Amazon Inc., 2009, AM WEB SERV OV SEC P
[2]  
Amazon Inc, AM EL COMP CLOUD
[3]  
[Anonymous], 2005, SOSP'05: Proceedings of the twentieth ACM symposium on Operating systems principles, DOI [10.1145/1095810.1095820, DOI 10.1145/1095810.1095820]
[4]  
[Anonymous], 2003, ACM SIGOPS OPERATING
[5]  
[Anonymous], 2003, P NETW DISTR SYST SE
[6]  
JOHNS MS, 1993, 1413 RFC
[7]   Lares: An architecture for secure active monitoring using virtualization [J].
Payne, Bryan D. ;
Carbone, Martim ;
Sharif, Monirul ;
Lee, Wenke .
PROCEEDINGS OF THE 2008 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, 2008, :233-247
[8]   Secure and flexible monitoring of virtual machines [J].
Payne, Bryan D. ;
Carbone, Martim D. P. de A. ;
Lee, Wenke .
TWENTY-THIRD ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2007, :385-397
[9]  
Payne Bryan D., LIBVMI
[10]  
Petroni J. N., 2007, P C COMP COMM SEC