Secure IDS Offloading with Nested Virtualization and Deep VM Introspection

Secure IDS Offloading with Nested Virtualization and Deep VM Introspection
复制标题

DOI:
10.1007/978-3-319-66399-9_17
复制
发表时间:
2017-09
期刊:
--
影响因子:
--
通讯作者:
Shohei Miyama;Kenichi Kourai
Shohei Miyama;Kenichi Kourai
中科院分区:
其他
文献类型:
--
作者:
Shohei Miyama;Kenichi Kourai

文献摘要

相似文献

为了对虚拟机安全执行入侵检测系统(IDS),使用了带有VM introspection (VMI)的IDS卸载。然而,在半可信的云中,在不可信的虚拟化系统中卸载IDS并不能保证已卸载的IDS正确运行。假设有一个受信任的管理程序,建议使用安全的IDS卸载,但是存在一些缺点,因为管理程序与不受信任的管理组件紧密耦合。在本文中,我们提出了一个称为dv - met的系统,它使用嵌套虚拟化来卸载虚拟系统外的ids。由于V-Met在虚拟机中运行的是一个不受信任的虚拟化系统,因此TCB (trusted computing base)的分离更加清晰和严格。V-Met可以防止ids受到不受信任的虚拟化系统的危害,并允许不受信任的管理员甚至管理虚拟机监控程序。此外,V-Met还为卸载的ids提供深度vmi,以获取虚拟机内目标虚拟机的内部状态,以运行虚拟化系统。我们已经在Xen中实现了V-Met,并确认卸载遗留IDS的性能与传统IDS卸载相当。
To securely execute intrusion detection systems (IDSes) for virtual machines (VMs), IDS offloading with VM introspection (VMI) is used. In semi-trusted clouds, however, IDS offloading inside an untrusted virtualized system does not guarantee that offloaded IDSes run correctly. Assuming a trusted hypervisor, secure IDS offloading has been proposed, but there are several drawbacks because the hypervisor is tightly coupled with untrusted management components. In this paper, we propose a system calledV-Met, which offloads IDSes outside the virtualized system usingnested virtualization. Since V-Met runs an untrusted virtualized system in a VM, the trusted computing base (TCB) is separated more clearly and strictly. V-Met can prevent IDSes from being compromised by untrusted virtualized systems and allows untrusted administrators to manage even the hypervisor. Furthermore, V-Met providesdeep VMIfor offloaded IDSes to obtain the internal state of target VMs inside the VM for running a virtualized system. We have implemented V-Met in Xen and confirmed that the performance of offloaded legacy IDSes was comparable to that in traditional IDS offloading.