课题基金 / 基金详情

CAREER: Bridging the Semantic Gap in Virtualization-based Security Solutions via Collaboration between Guest OS and Virtual Machine

CAREER: Bridging the Semantic Gap in Virtualization-based Security Solutions via Collaboration between Guest OS and Virtual Machine
职业:通过来宾操作系统和虚拟机之间的协作弥合基于虚拟化的安全解决方案中的语义差距
批准号:
1464801
负责人:
Daniela Oliveira
金额:
$22.68万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-07-01 至 2019-02-28

项目摘要

项目成果

Daniela Oliveira的其他基金

相似基金

相关文献

中文摘要
翻译
在过去的十年中,虚拟机被广泛用于与安全相关的应用,如入侵检测系统、恶意软件(恶意软件)分析器以及系统执行的安全记录和重放。VM是为模拟计算机硬件而设计的高级软件。在传统的使用模式中,安全解决方案被放置在虚拟机层中,该层拥有对系统资源的完全控制。来宾操作系统(OS)被认为很容易受到恶意软件的危害,并且在不知道虚拟化的情况下运行。这种方法的代价是语义鸿沟问题,这阻碍了基于虚拟化的安全解决方案的开发和广泛部署:来宾操作系统(高级语义信息)和VM(低级语义信息)观察到的状态存在显著差异。来宾操作系统处理进程和文件等抽象概念,而VM只能看到较低级别的抽象概念,如CPU和主存。为了获取有关来宾操作系统状态的信息,这些虚拟化解决方案使用一种称为自省的技术,通过该技术从外部(虚拟机层)检查来宾操作系统状态,通常是通过尝试将操作系统布局映射到这些解决方案可以分析它的内存区域。我们提出了一种执行自省的新方法,通过让传统上不知道虚拟化的来宾操作系统通过请求服务并在不同抽象级别中作为平等对等方通信数据和信息,主动与其下面的VM层协作。我们的方法允许开发更强大、更细粒度和更灵活的安全方法,它的安全性不亚于传统模型,因为自检工具还依赖于未被篡改的操作系统数据和代码来报告正确的结果。我们将设计、实现并向研究社区提供这种来宾操作系统和虚拟机层之间的协作架构,并使用这种架构来对抗各种类型的内核级恶意软件。其目标是通过利用社会信任在OS/VM层提炼主体和对象的信任/完整性值,从而增加攻击者的成本。在该体系结构中,客户操作系统和虚拟机通过防止篡改的特殊指令主动协作,请求服务并交换数据和信息。这将为恶意软件分析和防御打开可能性,这是目前不可能的(由于语义差距问题),包括防止来自键盘记录器等侵犯隐私的恶意软件的操作,减轻内核中某些类型的DoS攻击和面向返回的rootkit,通过利用社会信任来优化完整性级别并限制基于这些级别的系统资源,从而增加攻击者的成本,仅举几例。这项研究还将导致在位于缅因州的文理学院鲍登创建一个网络安全实验室。
英文摘要
In the last ten years virtual machines (VMs) have been extensively used for security-related applications, such as intrusion detection systems, malicious software (malware) analyzers and secure logging and replay of system execution. A VM is high-level software designed to emulate a computer's hardware. In the traditional usage model, security solutions are placed in a VM layer, which has complete control of the system resources. The guest operating system (OS) is considered to be easily compromised by malware and runs unaware of virtualization. The cost of this approach is the semantic gap problem, which hinders the development and widespread deployment of virtualization-based security solutions: there is significant difference between the state observed by the guest OS (high level semantic information) and by the VM (low level semantic information). The guest OS works on abstractions such as processes and files, while the VM can only see lower-level abstractions, such as CPU and main memory. To obtain information about the guest OS state these virtualization solutions use a technique called introspection, by which the guest OS state is inspected from the outside (VM layer), usually by trying build a map of the OS layout to an area of memory where these solutions can analyze it. We propose a new way to perform introspection, by having the guest OS, traditionally unaware of virtualization, actively collaborate with a VM layer underneath it by requesting services and communicating data and information as equal peers in different levels of abstraction. Our approach allows for stronger and more fine-grained and flexible security approaches to be developed and it is no less secure than the traditional model, as introspection tools also depend on the OS data and code to be untampered to report correct results.We will design, implement and make available to the research community this collaborative architecture between a guest OS and a VM layer and employ such architecture to counter various types of kernel-level malware. The goal is to increase the cost for attackers by refining trust/integrity values for subjects and objects at OS/VM layers by leveraging social trust. In this architecture guest OS and a VM actively collaborate requesting services and exchanging data and information through special instructions protected from tampering. This will open up possibilities for malware analysis and defense that are not currently possible (due to the semantic gap problem) including, preventing the actions from privacy-invasion malware like keyloggers, mitigating certain types of DoS attacks in the kernel and return-oriented rootkits, increasing the costs for attackers by leveraging social trust to refine integrity levels and restrict systems resources based on them, just to name a few. This research will also lead to the creation of a cyber security laboratory at Bowdoin, a liberal arts college located in Maine.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Intergovernmental Personnel Award: Daniela Oliveira
  • 批准号:
    2128814
  • 项目类别:
    Intergovernmental Personnel Award
  • 资助金额:
    $22.85万
  • 财政年份:
    2021
  • 负责人:
    Daniela Oliveira
  • 依托单位:
A Workshop US-Brazil on Cyber Security and Privacy
  • 批准号:
    1552059
  • 项目类别:
    Standard Grant
  • 资助金额:
    $10.0万
  • 财政年份:
    2015
  • 负责人:
    Daniela Oliveira
  • 依托单位:
TWC: Medium: Collaborative: Developer Crowdsourcing: Capturing, Understanding, and Addressing Security-related Blind Spots in APIs
  • 批准号:
    1513572
  • 项目类别:
    Standard Grant
  • 资助金额:
    $42.3万
  • 财政年份:
    2015
  • 负责人:
    Daniela Oliveira
  • 依托单位:
EAGER: Age-Targeted Automated Cueing Against Cyber Social Engineering Attacks
  • 批准号:
    1450624
  • 项目类别:
    Standard Grant
  • 资助金额:
    $24.55万
  • 财政年份:
    2014
  • 负责人:
    Daniela Oliveira
  • 依托单位:
海外基金