DocumentCode
244357
Title
FACE-CHANGE: Application-Driven Dynamic Kernel View Switching in a Virtual Machine
Author
Zhongshu Gu ; Saltaformaggio, Brendan ; Xiangyu Zhang ; Dongyan Xu
Author_Institution
Dept. of Comput. Sci. & CERIAS, Purdue Univ., West Lafayette, IN, USA
fYear
2014
fDate
23-26 June 2014
Firstpage
491
Lastpage
502
Abstract
Kernel minimization has already been established as a practical approach to reducing the trusted computing base. Existing solutions have largely focused on whole-system profiling - generating a globally minimum kernel image that is being shared by all applications. However, since different applications use only part of the kernel´s code base, the minimized kernel still includes an unnecessarily large attack surface. Furthermore, once the static minimized kernel is generated, it is not flexible enough to adapt to an altered execution environment (e.g., new workload). FACE-CHANGE is a virtualization-based system to facilitate dynamic switching at runtime among multiple minimized kernels, each customized for an individual application. Based on precedent profiling results, FACE-CHANGE transparently presents a customized kernel view for each application to confine its reach ability of kernel code. In the event that the application exceeds this boundary, FACE-CHANGE is able to recover the missing code and back trace its attack/exception provenance to analyze the anomalous behavior.
Keywords
operating system kernels; trusted computing; virtual machines; virtualisation; Face-Change; anomalous behavior analysis; application-driven dynamic kernel view switching; dynamic switching; globally minimum kernel image; kernel minimization; multiple minimized kernels; trusted computing base; virtual machine; virtualization-based system; whole-system profiling; Context; Indexes; Kernel; Loading; Minimization; Runtime; Switches; Attack Provenance; Attack Surface Minimization; Virtualization;
fLanguage
English
Publisher
ieee
Conference_Titel
Dependable Systems and Networks (DSN), 2014 44th Annual IEEE/IFIP International Conference on
Conference_Location
Atlanta, GA
Type
conf
DOI
10.1109/DSN.2014.52
Filename
6903605
Link To Document