Hiding File Manipulation of Essential Services by System Call Proxy

Hiding File Manipulation of Essential Services by System Call Proxy
复制标题

通过系统调用代理隐藏基本服务的文件操作

DOI:
10.1007/978-3-319-98530-5_76
复制
发表时间:
2018
期刊:
Lecture Notes on Data Engineering and Communications Technologies
影响因子:
--
通讯作者:
Yamauchi Toshihiro
Yamauchi Toshihiro
中科院分区:
--
文献类型:
--
作者:
Sato Masaya;Taniguchi Hideo;Yamauchi Toshihiro

文献摘要

相似文献

安全软件或日志程序经常受到攻击,因为它们是攻击者的障碍。保护这些基本服务免受攻击对于预防和减轻损害至关重要。隐藏与基本服务相关的信息,例如文件和进程的信息,可以帮助阻止对这些服务的攻击。本文提出了一种对基本服务隐藏文件操作的方法。该方法使文件对除其对应的基本服务外的所有服务不可见,并在虚拟机环境中提供对这些文件的访问方法。在建议的方法中,对这些文件的系统调用由另一个VM上的代理进程执行。原系统调用不在原虚拟机的操作系统中执行,但文件访问的结果返回给原进程。这样,基本服务的文件就被放在了另一个虚拟机上,原虚拟机上的其他进程无法访问这些文件。因此,本文提出的方法可以防止或阻止基于文件信息监控的关键业务的识别。
Security software or logging programs are frequently attacked because they are an obstruction to attackers. Protecting these essential services from attack is crucial to preventing and mitigating damage. Hiding information related to essential services, such as that of the files and processes, can help to deter attacks on these services. This paper proposes a method of hiding file manipulation for essential services. The method makes the files invisible to all services except their corresponding essential services and provides access methods to those files in a virtual machine (VM) environment. In the proposed method, system calls to those files are executed by a proxy process on the other VM. The original system call is not executed in the operating system of the original VM, however, the result of file access is returned to the original process. Thus, the files of essential services are placed on the other VM and other processes on the original VM cannot access to them. Therefore, the proposed method can prevent or deter identification of essential services based on file information monitoring.