Title :
PEDA: Comprehensive Damage Assessment for Production Environment Server Systems
Author :
Zhang, Shengzhi ; Jia, Xiaoqi ; Liu, Peng ; Jing, Jiwu
Author_Institution :
Dept. of Comput. Sci. & Eng., Pennsylvania State Univ., University Park, PA, USA
Abstract :
Analyzing the intrusion to production servers is an onerous and error-prone work for system security technicians. Existing tools or techniques are quite limited. For instance, system events tracking lacks completeness of intrusion propagation, while dynamic taint tracking is not feasible to be deployed due to significant runtime overhead. Thus, we propose production environment damage assessment (PEDA), a systematic approach to do postmortem intrusion analysis for production workload servers. PEDA replays the “has-been-infected” execution with high fidelity on a separate analyzing instrumentation platform to conduct the heavy workload analysis. Though the replayed execution runs atop the instrumentation platform (i.e., binary-translation-based virtual machine), PEDA allows the first-run execution to run atop the hardware-assisted virtual machine to ensure minimum runtime overhead. Our evaluation demonstrates the efficiency of the PEDA system with a runtime overhead as low as 5%. The real-life intrusion studies show the advantage of PEDA intrusion analysis over existing techniques.
Keywords :
file servers; security of data; virtual machines; PEDA; binary-translation-based virtual machine; comprehensive damage assessment; hardware-assisted virtual machine; has-been-infected execution; heavy workload analysis; intrusion analysis; intrusion propagation; production environment damage assessment; production environment server systems; production servers; system events tracking; system security; Checkpointing; Runtime; Security; Servers; Virtual machining; Forward and backward tracking; heterogeneous virtual machine (VM) migration; taint analysis;
Journal_Title :
Information Forensics and Security, IEEE Transactions on
DOI :
10.1109/TIFS.2011.2162062