Virtual machine monitor-based lightweight intrusion detection

Virtual machine monitor-based lightweight intrusion detection
复制标题

基于虚拟机监视器的轻量级入侵检测

DOI:
10.1145/2007183.2007189
复制
发表时间:
2011
期刊:
ACM SIGOPS Oper. Syst. Rev.
影响因子:
--
通讯作者:
D. Kaeli
D. Kaeli
中科院分区:
--
文献类型:
--
作者:
Fatemeh Azmandian;Micha Moffie;Malak Alshawabkeh;Jennifer G. Dy;J. Aslam;D. Kaeli

文献摘要

被引文献

相似文献

随着虚拟化技术的普及,试图损害虚拟化计算资源的安全性和完整性的尝试也越来越多。反病毒软件和防火墙程序通常部署在来宾虚拟机中以检测恶意软件。这些安全措施在检测已知恶意软件方面很有效,但在防范新的入侵变种方面却收效甚微。入侵检测系统(IDS)可以用来检测恶意行为。大多数用于虚拟执行环境的入侵检测系统在应用程序或操作系统级别跟踪行为,使用虚拟化作为将其自身与受损的虚拟机隔离的手段。 在本文中,我们提出了一种新的方法来入侵检测的虚拟服务器环境,它只利用信息的虚拟机监视器(VMM)的角度来看。这样的IDS可以利用VMM的能力来隔离和管理多个虚拟机(VM),从而可以在跨VM的公共级别上提供对入侵的监视。与虚拟机环境入侵检测的最新进展相比,它还具有独特的优势。通过纯粹在VMM级别工作,IDS不依赖于对OS可见的结构或抽象(例如,文件系统),其易受攻击并可被恶意软件修改以包含损坏的信息(例如,Windows注册表)。此外,位于VMM中提供了部署的便利性,因为IDS没有绑定到特定的操作系统,并且可以透明地部署在不同的操作系统下。 由于VMM可用的信息和实际的应用程序行为之间的语义差距,我们采用数据挖掘技术的力量,从原始的,低层次的体系结构数据中提取有用的知识。在本文中,我们表明,通过完全在VMM级别工作,我们能够捕获足够的信息来描述正常的执行,并确定异常恶意行为的存在。我们对300多个真实世界的恶意软件和漏洞的实验表明,VMM级数据中嵌入了足够的信息,可以准确检测恶意攻击,并具有可接受的误报率。
As virtualization technology gains in popularity, so do attempts to compromise the security and integrity of virtualized computing resources. Anti-virus software and firewall programs are typically deployed in the guest virtual machine to detect malicious software. These security measures are effective in detecting known malware, but do little to protect against new variants of intrusions. Intrusion detection systems (IDSs) can be used to detect malicious behavior. Most intrusion detection systems for virtual execution environments track behavior at the application or operating system level, using virtualization as a means to isolate themselves from a compromised virtual machine. In this paper, we present a novel approach to intrusion detection of virtual server environments which utilizes only information available from the perspective of the virtual machine monitor (VMM). Such an IDS can harness the ability of the VMM to isolate and manage several virtual machines (VMs), making it possible to provide monitoring of intrusions at a common level across VMs. It also offers unique advantages over recent advances in intrusion detection for virtual machine environments. By working purely at the VMM-level, the IDS does not depend on structures or abstractions visible to the OS (e.g., file systems), which are susceptible to attacks and can be modified by malware to contain corrupted information (e.g., the Windows registry). In addition, being situated within the VMM provides ease of deployment as the IDS is not tied to a specific OS and can be deployed transparently below different operating systems. Due to the semantic gap between the information available to the VMM and the actual application behavior, we employ the power of data mining techniques to extract useful nuggets of knowledge from the raw, low-level architectural data. We show in this paper that by working entirely at the VMM-level, we are able to capture enough information to characterize normal executions and identify the presence of abnormal malicious behavior. Our experiments on over 300 real-world malware and exploits illustrate that there is sufficient information embedded within the VMM-level data to allow accurate detection of malicious attacks, with an acceptable false alarm rate.