课题基金 / 基金详情

CAREER: Bridging the Semantic Gap in Virtualization-based Security Solutions via Collaboration between Guest OS and Virtual Machine

CAREER: Bridging the Semantic Gap in Virtualization-based Security Solutions via Collaboration between Guest OS and Virtual Machine
职业:通过来宾操作系统和虚拟机之间的协作弥合基于虚拟化的安全解决方案中的语义差距
批准号:
1464801
负责人:
Daniela Oliveira
金额:
$22.68万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-07-01 至 2019-02-28

项目摘要

项目成果

Daniela Oliveira的其他基金

相似基金

相关文献

中文摘要
翻译
在过去十年中,虚拟机(vm)被广泛用于与安全相关的应用程序,例如入侵检测系统、恶意软件(恶意软件)分析器以及系统执行的安全日志记录和重播。虚拟机是设计用来模拟计算机硬件的高级软件。在传统的使用模型中,安全解决方案被放置在虚拟机层,虚拟机层完全控制系统资源。客户操作系统(OS)被认为很容易受到恶意软件的攻击,并且在不知道虚拟化的情况下运行。这种方法的代价是语义差距问题,它阻碍了基于虚拟化的安全解决方案的开发和广泛部署:客户机操作系统观察到的状态(高级语义信息)和VM观察到的状态(低级语义信息)之间存在显著差异。客户操作系统处理诸如进程和文件之类的抽象,而虚拟机只能看到较低级别的抽象,例如CPU和主存。为了获取有关客户机操作系统状态的信息,这些虚拟化解决方案使用一种称为自省的技术,通过这种技术,从外部(VM层)检查客户机操作系统状态,通常是通过尝试构建操作系统布局到内存区域的映射,这些解决方案可以在内存区域对其进行分析。我们提出了一种执行内省的新方法,通过让传统上不知道虚拟化的客户操作系统,通过请求服务和在不同抽象级别上作为平等对等体通信数据和信息,积极地与它下面的VM层协作。我们的方法允许开发更强、更细粒度和更灵活的安全方法,并且它的安全性并不亚于传统模型,因为自省工具也依赖于未被篡改的操作系统数据和代码来报告正确的结果。我们将设计、实现并向研究社区提供客户机操作系统和VM层之间的协作架构,并使用这种架构来对抗各种类型的内核级恶意软件。其目标是通过利用社会信任来优化OS/VM层主体和对象的信任/完整性值,从而增加攻击者的成本。在这种体系结构中,客户机操作系统和虚拟机主动协作,请求服务,并通过防止篡改的特殊指令交换数据和信息。这将打开恶意软件分析和防御的可能性,目前不可能(由于语义差距问题),包括,防止像键盘记录器这样的隐私入侵恶意软件的行为,减轻内核和面向返回的rootkits中的某些类型的DoS攻击,增加攻击者的成本通过利用社会信任来完善完整性级别和限制基于它们的系统资源,仅举几例。这项研究还将在缅因州的文理学院鲍登(Bowdoin)建立一个网络安全实验室。
英文摘要
In the last ten years virtual machines (VMs) have been extensively used for security-related applications, such as intrusion detection systems, malicious software (malware) analyzers and secure logging and replay of system execution. A VM is high-level software designed to emulate a computer's hardware. In the traditional usage model, security solutions are placed in a VM layer, which has complete control of the system resources. The guest operating system (OS) is considered to be easily compromised by malware and runs unaware of virtualization. The cost of this approach is the semantic gap problem, which hinders the development and widespread deployment of virtualization-based security solutions: there is significant difference between the state observed by the guest OS (high level semantic information) and by the VM (low level semantic information). The guest OS works on abstractions such as processes and files, while the VM can only see lower-level abstractions, such as CPU and main memory. To obtain information about the guest OS state these virtualization solutions use a technique called introspection, by which the guest OS state is inspected from the outside (VM layer), usually by trying build a map of the OS layout to an area of memory where these solutions can analyze it. We propose a new way to perform introspection, by having the guest OS, traditionally unaware of virtualization, actively collaborate with a VM layer underneath it by requesting services and communicating data and information as equal peers in different levels of abstraction. Our approach allows for stronger and more fine-grained and flexible security approaches to be developed and it is no less secure than the traditional model, as introspection tools also depend on the OS data and code to be untampered to report correct results.We will design, implement and make available to the research community this collaborative architecture between a guest OS and a VM layer and employ such architecture to counter various types of kernel-level malware. The goal is to increase the cost for attackers by refining trust/integrity values for subjects and objects at OS/VM layers by leveraging social trust. In this architecture guest OS and a VM actively collaborate requesting services and exchanging data and information through special instructions protected from tampering. This will open up possibilities for malware analysis and defense that are not currently possible (due to the semantic gap problem) including, preventing the actions from privacy-invasion malware like keyloggers, mitigating certain types of DoS attacks in the kernel and return-oriented rootkits, increasing the costs for attackers by leveraging social trust to refine integrity levels and restrict systems resources based on them, just to name a few. This research will also lead to the creation of a cyber security laboratory at Bowdoin, a liberal arts college located in Maine.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Intergovernmental Personnel Award: Daniela Oliveira
  • 批准号:
    2128814
  • 项目类别:
    Intergovernmental Personnel Award
  • 资助金额:
    $22.85万
  • 财政年份:
    2021
  • 负责人:
    Daniela Oliveira
  • 依托单位:
A Workshop US-Brazil on Cyber Security and Privacy
  • 批准号:
    1552059
  • 项目类别:
    Standard Grant
  • 资助金额:
    $10.0万
  • 财政年份:
    2015
  • 负责人:
    Daniela Oliveira
  • 依托单位:
TWC: Medium: Collaborative: Developer Crowdsourcing: Capturing, Understanding, and Addressing Security-related Blind Spots in APIs
  • 批准号:
    1513572
  • 项目类别:
    Standard Grant
  • 资助金额:
    $42.3万
  • 财政年份:
    2015
  • 负责人:
    Daniela Oliveira
  • 依托单位:
EAGER: Age-Targeted Automated Cueing Against Cyber Social Engineering Attacks
  • 批准号:
    1450624
  • 项目类别:
    Standard Grant
  • 资助金额:
    $24.55万
  • 财政年份:
    2014
  • 负责人:
    Daniela Oliveira
  • 依托单位:
海外基金