Phase Space Detection of Virtual Machine Cyber Events Through Hypervisor-Level System Call Analysis

Phase Space Detection of Virtual Machine Cyber Events Through Hypervisor-Level System Call Analysis
复制标题

通过虚拟机管理程序级系统调用分析进行虚拟机网络事件的相空间检测

DOI:
10.1109/icdis.2018.00034
复制
发表时间:
2018
期刊:
2018 1st International Conference on Data Intelligence and Security (ICDIS)
影响因子:
--
通讯作者:
Charles Hubbard
Charles Hubbard
中科院分区:
--
文献类型:
--
作者:
Joel A. Dawson;J. McDonald;L. Hively;T. Andel;M. Yampolskiy;Charles Hubbard

文献摘要

参考文献

被引文献

相似文献

云计算生态系统的发展为企业和消费者提供了许多新的机会;然而,这种新的计算环境也带来了新的风险,人们对基于云的系统架构中固有的安全危险给予了很多关注。然而,研究人员在解决高级持续威胁入侵的风险方面几乎没有采取任何措施,特别是在 Rootkit 的使用方面,Rootkit 是一种功能强大、隐蔽的恶意软件,在网络犯罪分子和民族国家行为者中越来越受欢迎。这些程序通过获取 root 权限来威胁系统,然后使用各种隐秘策略,逃避现代反恶意软件工具的检测和删除。在这项研究中,我们验证了橡树岭国家实验室 Beholder 项目的方法适用于正在运行的虚拟机中检测 rootkit 的环境。我们通过收集和分析在虚拟机管理程序级别收集的系统调用来做到这一点。该分析采用新颖的非线性相空间算法来导出时间序列网络动力学,然后通过比较标称和测试行为概况,使用这些动力学来表征潜在的异常系统行为。我们的结果表明,该技术可以有效地标记受感染机器和未受感染机器的时间轨迹之间的差异,从而表明存在正在运行的 Rootkit。
The growth of the cloud computing ecosystem has afforded many new opportunities to businesses and consumers alike; however, with this new computing context comes new risks, and much attention has been given to the security dangers inherent in the architecture of cloud-based systems. Researchers, however, have done little to address the risk of advanced persistent threat intrusions, specifically in regard to the use of rootkits, which are powerful, stealthy pieces of malware that have grown in popularity with cybercriminals and nation state actors. These programs threaten a system by acquiring root privilege and then, using a variety of stealth tactics, evading detection and removal by modern anti-malware tools. In this research, we validate that the approach of Oak Ridge National Laboratory's Beholder project is applicable to the context of rootkit detection within a running virtual machine. We do this by collecting and analyzing system calls collected on the hypervisor level. The analysis employs a novel nonlinear, phase-space algorithm to derive time-serial cyber dynamics, and then uses these dynamics to characterize potentially anomalous system behavior through the comparison of nominal and test behavior profiles. Our results demonstrate that this technique is effective in flagging variance between the timing traces of an infected and an uninfected machine, thus indicating the presence of a running rootkit.
DOI: 10.1016/j.jss.2012.12.025
发表时间: 2013-09
期刊: J. Syst. Softw.
影响因子: --
作者:
M. Ryan
通讯作者: M. Ryan