KVMIveggur: Flexible, secure, and efficient support for self-service virtual machine introspection

被引:3
|
作者
Sentanoe, Stewart [1 ]
Dangl, Thomas [1 ]
Reiser, Hans P. [1 ,2 ]
机构
[1] Univ Passau, Innstr 43, D-94032 Passau, Germany
[2] Reykjavik Univ, Menntavegur 1, IS-102 Reykjavik, Iceland
来源
FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION | 2022年 / 42卷
关键词
Virtual machine introspection; Virtual machine; KVM; Access control;
D O I
10.1016/j.fsidi.2022.301397
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Virtual machine introspection (VMI) has evolved into a widely used technique for purposes such as digital forensics, intrusion detection, and malware analysis. The recent integration of enhanced VMI capabilities into KVM further facilitates the use of VMI. A significant obstacle, however, remains: VMI usually requires highly privileged access to the host system. Existing research prototypes that address this issue either target only the Xen hypervisor, are extremely slow, offer only a subset of the desired functionality, or are hard to deploy in real-life systems. We present our flexible KVMIveggur architecture as a novel solution to these challenges. It offers three flavors of isolation (using containers, virtual machines, and network remote access) that all enable access control for secure self-service VMI in cloud environments. It enables the full use of passive and active VMI, supports continuous monitoring also during live VM migration, and can be tailored for low overhead and minimal resource utilization on the host system. The experimental evaluation of our prototype demonstrates the feasibility and the efficiency of our approach and provides detailed insights into the differences between the three flavors. (C) 2022 The Authors. Published by Elsevier Ltd.
引用
收藏
页数:9
相关论文
共 9 条
  • [1] VMIFresh: Efficient and fresh caches for virtual machine introspection
    Dangl, Thomas
    Sentanoe, Stewart
    Reiser, Hans P.
    COMPUTERS & SECURITY, 2023, 135
  • [2] VMIFresh: Efficient and Fresh Caches for Virtual Machine Introspection
    Dangl, Thomas
    Sentanoe, Stewart
    Reiser, Hans P.
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022, 2022,
  • [3] CryptVMI: A Flexible and Encrypted Virtual Machine Introspection System in the Cloud
    Yao, Fangzhou
    Sprabery, Read
    Campbell, Roy H.
    SCC'14: PROCEEDINGS OF THE 2ND INTERNATIONAL WORKSHOP ON SECURITY IN CLOUD COMPUTING, 2014, : 11 - 17
  • [4] Benchmarking Hyper-Breakpoints for Efficient Virtual Machine Introspection
    Beierlieb, Lukas
    Schmitz, Alexander
    Springer, Raphael
    Dietrich, Christian
    Ifflaender, Lukas
    ELECTRONICS, 2025, 14 (03):
  • [5] Enforcing Access Controls for the Cryptographic Cloud Service Invocation Based on Virtual Machine Introspection
    Jiang, Fangjie
    Cai, Quanwei
    Guan, Le
    Lin, Jingqiang
    INFORMATION SECURITY (ISC 2018), 2018, 11060 : 213 - 230
  • [6] VMIGuard: Detecting and Preventing Service Integrity Violations by Malicious Insiders Using Virtual Machine Introspection
    Sentanoe, Stewart
    Taubmann, Benjamin
    Reiser, Hans P.
    SECURE IT SYSTEMS, NORDSEC 2019, 2019, 11875 : 271 - 282
  • [7] Efficient virtual machine support of runtime structural reflection
    Ortin, Francisco
    Redondo, Jose Manuel
    Garcia Perez-Schofield, J. Baltasar
    SCIENCE OF COMPUTER PROGRAMMING, 2009, 74 (10) : 836 - 860
  • [8] Virtual machine support for zero-loss Internet service recovery and upgrade
    Chang, Da-Wei
    Hsieh, Cheng-En
    Chen, Yan-Pai
    Chiu, Kwo-Cheng
    SOFTWARE-PRACTICE & EXPERIENCE, 2007, 37 (13): : 1349 - 1376
  • [9] Review and analysis of secure energy efficient resource optimization approaches for virtual machine migration in cloud computing
    Kaur H.
    Anand A.
    Measurement: Sensors, 2022, 24