DocumentCode :
2183656
Title :
Towards Thwarting Unauthorized Network Accesses with a Feather-Weight Hypervisor
Author :
Yan Wen ; Jinjing Zhao ; Hua Chen ; Lufeng Zhang
Author_Institution :
Beijing Inst. of Syst. Eng., Beijing, China
fYear :
2013
fDate :
16-19 Dec. 2013
Firstpage :
613
Lastpage :
620
Abstract :
In the cloud computing environment, most of applications rely on the network access to achieve their functionalities. Untrusted or vulnerable cloud applications will incur unauthorized network accesses which may bring on the user information leakage or other threats. In this paper, we propose a novel feather-weight hardware-assisted hypervisor, namely NFVisor (Network Filter Hypervisor), to thwart such unauthorized network accesses. Compared to previous host-based approaches, NFVisor offers two distinct advantages: preinstalled commodity OS compatibility and non-by passable manipulation of network accesses. Unlike typical hypervisors, deploying NFVisor does not require OS reinstallation. By intercepting the low-level interactions between the OS and the hardware, NFVisor can manipulate the network accesses at the hypervisor layer instead of the OS layer, which is subvertable for the privileged malware. Our functionality evaluation shows NFVisor can impede unauthorized network connections effectively while the performance evaluation shows desktop-oriented workloads achieve 94.12% of native speed on average.
Keywords :
cloud computing; invasive software; operating system kernels; NFVisor; OS kernel; OS layer; cloud computing environment; desktop-oriented workloads; feather-weight hardware-assisted hypervisor; host-based approach; low-level interactions; malware; network filter hypervisor; nonby passable manipulation; preinstalled commodity OS compatibility; thwarting unauthorized network accesses; user information leakage; Computer architecture; Hardware; Kernel; Malware; Virtual machine monitors; Virtualization; Virtual machine; hypervisor; network;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cloud Computing and Big Data (CloudCom-Asia), 2013 International Conference on
Conference_Location :
Fuzhou
Print_ISBN :
978-1-4799-2829-3
Type :
conf
DOI :
10.1109/CLOUDCOM-ASIA.2013.105
Filename :
6821058
Link To Document :
بازگشت