CAREER: Bridging the Semantic Gap in Virtualization-based Security Solutions via Collaboration between Guest OS and Virtual Machine
CAREER: Bridging the Semantic Gap in Virtualization-based Security Solutions via Collaboration between Guest OS and Virtual Machine
批准号:
1149730
负责人:
Daniela Oliveira
金额:
$40.45万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2012
资助国家:
美国
项目状态:
已结题
起止时间:
2012-03-01 至 2014-11-30
中文摘要
在过去的十年中,虚拟机(VM)已经被广泛用于安全相关的应用,诸如入侵检测系统、恶意软件(malware)分析器以及系统执行的安全记录和重放。虚拟机是设计用于模拟计算机硬件的高级软件。在传统的使用模型中,安全解决方案放置在虚拟机层中,该层对系统资源拥有完全控制权。来宾操作系统(OS)被认为很容易受到恶意软件的危害,并且在运行时不知道虚拟化。这种方法的代价是语义差距问题,这阻碍了基于虚拟化的安全解决方案的开发和广泛部署:客户操作系统(高级语义信息)和VM(低级语义信息)观察到的状态之间存在显着差异。客户机操作系统处理进程和文件等抽象,而虚拟机只能看到较低级别的抽象,如CPU和主存。为了获得关于客户操作系统状态的信息,这些虚拟化解决方案使用称为内省的技术,通过该技术,从外部检查客户操作系统状态(虚拟机层),通常是通过尝试构建操作系统布局到这些解决方案可以分析它的内存区域的映射。我们提出了一种新的方法来执行内省,通过让客户操作系统,传统上不知道虚拟化,通过请求服务和在不同抽象级别上作为平等对等体传递数据和信息,与其下的VM层积极协作。我们的方法允许开发更强大,更细粒度和更灵活的安全方法,并且它的安全性不低于传统模型,因为内省工具也依赖于操作系统数据和代码未被篡改以报告正确的结果。实现并向研究团体提供客户OS和VM层之间的这种协作架构,并采用这种架构来对抗各种类型的内核级恶意软件其目标是通过利用社会信任来改进OS/VM层主体和对象的信任/完整性值,从而增加攻击者的成本。在这种体系结构中,客户操作系统和虚拟机通过防止篡改的特殊指令主动协作请求服务并交换数据和信息。这将为目前不可能的恶意软件分析和防御开辟可能性(由于语义差距问题),包括防止键盘记录器等隐私入侵恶意软件的行为,减轻内核中某些类型的DoS攻击和返回导向的rootkit,通过利用社会信任来提高完整性级别并限制基于它们的系统资源来增加攻击者的成本。这项研究还将导致在位于缅因州的文科学院鲍登建立一个网络安全实验室。
英文摘要
In the last ten years virtual machines (VMs) have been extensively used for security-related applications, such as intrusion detection systems, malicious software (malware) analyzers and secure logging and replay of system execution. A VM is high-level software designed to emulate a computer's hardware. In the traditional usage model, security solutions are placed in a VM layer, which has complete control of the system resources. The guest operating system (OS) is considered to be easily compromised by malware and runs unaware of virtualization. The cost of this approach is the semantic gap problem, which hinders the development and widespread deployment of virtualization-based security solutions: there is significant difference between the state observed by the guest OS (high level semantic information) and by the VM (low level semantic information). The guest OS works on abstractions such as processes and files, while the VM can only see lower-level abstractions, such as CPU and main memory. To obtain information about the guest OS state these virtualization solutions use a technique called introspection, by which the guest OS state is inspected from the outside (VM layer), usually by trying build a map of the OS layout to an area of memory where these solutions can analyze it. We propose a new way to perform introspection, by having the guest OS, traditionally unaware of virtualization, actively collaborate with a VM layer underneath it by requesting services and communicating data and information as equal peers in different levels of abstraction. Our approach allows for stronger and more fine-grained and flexible security approaches to be developed and it is no less secure than the traditional model, as introspection tools also depend on the OS data and code to be untampered to report correct results.We will design, implement and make available to the research community this collaborative architecture between a guest OS and a VM layer and employ such architecture to counter various types of kernel-level malware. The goal is to increase the cost for attackers by refining trust/integrity values for subjects and objects at OS/VM layers by leveraging social trust. In this architecture guest OS and a VM actively collaborate requesting services and exchanging data and information through special instructions protected from tampering. This will open up possibilities for malware analysis and defense that are not currently possible (due to the semantic gap problem) including, preventing the actions from privacy-invasion malware like keyloggers, mitigating certain types of DoS attacks in the kernel and return-oriented rootkits, increasing the costs for attackers by leveraging social trust to refine integrity levels and restrict systems resources based on them, just to name a few. This research will also lead to the creation of a cyber security laboratory at Bowdoin, a liberal arts college located in Maine.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Intergovernmental Personnel Award: Daniela Oliveira
-
批准号:2128814
-
项目类别:Intergovernmental Personnel Award
-
资助金额:$22.85万
-
财政年份:2021
-
负责人:Daniela Oliveira
-
依托单位:
A Workshop US-Brazil on Cyber Security and Privacy
-
批准号:1552059
-
项目类别:Standard Grant
-
资助金额:$10.0万
-
财政年份:2015
-
负责人:Daniela Oliveira
-
依托单位:
TWC: Medium: Collaborative: Developer Crowdsourcing: Capturing, Understanding, and Addressing Security-related Blind Spots in APIs
-
批准号:1513572
-
项目类别:Standard Grant
-
资助金额:$42.3万
-
财政年份:2015
-
负责人:Daniela Oliveira
-
依托单位:
EAGER: Age-Targeted Automated Cueing Against Cyber Social Engineering Attacks
-
批准号:1450624
-
项目类别:Standard Grant
-
资助金额:$24.55万
-
财政年份:2014
-
负责人:Daniela Oliveira
-
依托单位:
CAREER: Bridging the Semantic Gap in Virtualization-based Security Solutions via Collaboration between Guest OS and Virtual Machine
-
批准号:1464801
-
项目类别:Continuing Grant
-
资助金额:$22.68万
-
财政年份:2014
-
负责人:Daniela Oliveira
-
依托单位:
海外基金