Secure Offloading of User-level IDS with VM-compatible OS Emulation Layers for Intel SGX

Secure Offloading of User-level IDS with VM-compatible OS Emulation Layers for Intel SGX
复制标题

DOI:
10.1109/cloud55607.2022.00035
复制
发表时间:
2022-07
期刊:
2022 IEEE 15th International Conference on Cloud Computing (CLOUD)
影响因子:
--
通讯作者:
Takumi Kawamura;Kenichi Kourai
Takumi Kawamura;Kenichi Kourai
中科院分区:
其他
文献类型:
--
作者:
Takumi Kawamura;Kenichi Kourai

文献摘要

相似文献

由于云结构即服务云提供的虚拟机(VM)经常遭受攻击,因此需要使用入侵检测系统(IDS)对其进行监控。为了安全执行基于主机的IDS(HIDS),IDS卸载用于在目标VM之外运行IDS,但卸载的IDS仍然可能受到攻击。为解决此问题,已提出使用英特尔SGX进行安全IDS卸载。然而,IDS开发需要内核级编程,这对于大多数IDS开发人员来说是困难的。本文提出了SCwatcher,使用户级的HIDS上运行的操作系统(OS)的安全卸载使用虚拟机兼容的操作系统仿真层SGX。SCwatcher提供了目标VM中使用的标准OS接口,用于安全区内IDS。特别是,称为vProcFS的虚拟proc文件系统使用VM内省分析OS数据,并返回目标VM内部的系统信息。我们已经使用Xen实现了SCwatcher,支持SGX虚拟化和两种类型的SGX操作系统仿真层,称为SCONE和Occlum。然后,我们证实了SCwatcher可以卸载遗留的HIDS,并表明其性能可以与不安全的IDS卸载相媲美。
Since virtual machines (VMs) provided by Infrastructure-as-a-Service clouds often suffer from attacks, they need to be monitored using intrusion detection systems (IDS). For secure execution of host-based IDS (HIDS), IDS offloading is used to run IDS outside target VMs, but offloaded IDS can still be attacked. To address this issue, secure IDS offloading using Intel SGX has been proposed. However, IDS development requires kernel-level programming, which is difficult for most IDS developers. This paper proposes SCwatcher for enabling user-level HIDS running on top of the operating system (OS) to be securely offloaded using VM-compatible OS emulation layers for SGX. SCwatcher provides the standard OS interface used in a target VM to in-enclave IDS. Especially, the virtual proc filesystem called vProcFS analyzes OS data using VM introspection and returns the system information inside the target VM. We have implemented SCwatcher using Xen supporting SGX virtualization and two types of OS emulation layers for SGX called SCONE and Occlum. Then, we confirmed that SCwatcher could offload legacy HIDS and showed that the performance could be comparable to insecure IDS offloading.