DocumentCode :
244357
Title :
FACE-CHANGE: Application-Driven Dynamic Kernel View Switching in a Virtual Machine
Author :
Zhongshu Gu ; Saltaformaggio, Brendan ; Xiangyu Zhang ; Dongyan Xu
Author_Institution :
Dept. of Comput. Sci. & CERIAS, Purdue Univ., West Lafayette, IN, USA
fYear :
2014
fDate :
23-26 June 2014
Firstpage :
491
Lastpage :
502
Abstract :
Kernel minimization has already been established as a practical approach to reducing the trusted computing base. Existing solutions have largely focused on whole-system profiling - generating a globally minimum kernel image that is being shared by all applications. However, since different applications use only part of the kernel´s code base, the minimized kernel still includes an unnecessarily large attack surface. Furthermore, once the static minimized kernel is generated, it is not flexible enough to adapt to an altered execution environment (e.g., new workload). FACE-CHANGE is a virtualization-based system to facilitate dynamic switching at runtime among multiple minimized kernels, each customized for an individual application. Based on precedent profiling results, FACE-CHANGE transparently presents a customized kernel view for each application to confine its reach ability of kernel code. In the event that the application exceeds this boundary, FACE-CHANGE is able to recover the missing code and back trace its attack/exception provenance to analyze the anomalous behavior.
Keywords :
operating system kernels; trusted computing; virtual machines; virtualisation; Face-Change; anomalous behavior analysis; application-driven dynamic kernel view switching; dynamic switching; globally minimum kernel image; kernel minimization; multiple minimized kernels; trusted computing base; virtual machine; virtualization-based system; whole-system profiling; Context; Indexes; Kernel; Loading; Minimization; Runtime; Switches; Attack Provenance; Attack Surface Minimization; Virtualization;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems and Networks (DSN), 2014 44th Annual IEEE/IFIP International Conference on
Conference_Location :
Atlanta, GA
Type :
conf
DOI :
10.1109/DSN.2014.52
Filename :
6903605
Link To Document :
بازگشت