Custos: Practical Tamper-Evident Auditing of Operating Systems Using Trusted Execution

Custos: Practical Tamper-Evident Auditing of Operating Systems Using Trusted Execution
复制标题

DOI:
10.14722/ndss.2020.24065
复制
发表时间:
2020
期刊:
Proceedings 2020 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Riccardo Paccagnella;Pubali Datta;Wajih Ul Hassan;Adam Bates;Christopher W. Fletcher;Andrew K. Miller
Riccardo Paccagnella;Pubali Datta;Wajih Ul Hassan;Adam Bates;Christopher W. Fletcher;Andrew K. Miller
中科院分区:
其他
文献类型:
--
作者:
Riccardo Paccagnella;Pubali Datta;Wajih Ul Hassan;Adam Bates;Christopher W. Fletcher;Andrew K. Miller

文献摘要

被引文献

相似文献

—系统审核是调查和响应安全事件时的一个核心问题。不幸的是,攻击者在入侵后经常进行反取证活动,从系统日志中掩盖他们的踪迹,以挫败调查人员的努力。虽然整个行业和文献中已经出现了各种防篡改日志记录解决方案,但这些技术不能满足系统层审计框架的操作和可扩展性要求。在这项工作中,我们介绍了 CUSTOS,一个用于检测系统日志篡改的实用框架。 C USTOS 由防篡改日志记录层和去中心化审计协议组成。前者可以通过对底层日志框架进行最小的更改来验证日志完整性,而后者可以近乎实时地检测企业级网络内的日志完整性违规情况。 C USTOS 之所以实用,是因为我们观察到我们可以将加密日志承诺的成本与创建和存储日志事件的行为分离,而无需牺牲安全性,利用现成的可信执行环境的功能。每秒支持超过一百万个事件,我们表明 C USTOS 的防篡改日志记录协议比以前的解决方案快三个数量级 (1000 × ),并且与密集工作负载上的不安全日志记录相比,仅产生 2% 到 7% 的运行时开销。此外,我们还表明,即使存在强大的分布式对手,CUSTOS 的审计协议也可以近乎实时地检测违规行为,并且网络开销极小(3%)。我们对现实世界 APT 攻击场景的案例研究表明,C USTOS 迫使反取证攻击者陷入“双输”的境地,他们要么隐蔽且不篡改日志(可用于取证),要么擦除日志但随后
—System auditing is a central concern when investigating and responding to security incidents. Unfortunately, attackers regularly engage in anti-forensic activities after a break-in, covering their tracks from the system logs in order to frustrate the efforts of investigators. While a variety of tamper-evident logging solutions have appeared throughout the industry and the literature, these techniques do not meet the operational and scalability requirements of system-layer audit frameworks. In this work, we introduce C USTOS , a practical framework for the detection of tampering in system logs. C USTOS consists of a tamper-evident logging layer and a decentralized auditing protocol. The former enables the verification of log integrity with minimal changes to the underlying logging framework, while the latter enables near real-time detection of log integrity violations within an enterprise-class network. C USTOS is made practical by the observation that we can decouple the costs of cryptographic log commitments from the act of creating and storing log events, without trading off security, leveraging features of off-the-shelf trusted execution environments. Supporting over one million events per second, we show that C USTOS ’ tamper-evident logging protocol is three orders of magnitude (1000 × ) faster than prior solutions and incurs only between 2% and 7% runtime overhead over insecure logging on intensive workloads. Further, we show that C USTOS ’ auditing protocol can detect violations in near real-time even in the presence of a powerful distributed adversary and with minimal (3%) network overhead. Our case study on a real-world APT attack scenario demonstrates that C USTOS forces anti-forensic attackers into a “lose-lose” situation, where they can either be covert and not tamper with logs (which can be used for forensics), or erase logs but then